CVE-2017-7298: XSS
Published Mar 29, 2017
·Updated
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
Affected Software
2 affected components
composer/moodle/moodle>=3.2<=3.2.2
Moodle moodle=3.2.2
Event History
Mar 29, 2017
CVE Published
via MITRE·05:23 AM
Data Sourced
via MITRE·05:23 AM
Description
Data Sourced
via NVD·05:59 AM
DescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
via GitHub·03:22 AM
Frequently Asked Questions
1
What is the impact of CVE-2017-7298?
CVE-2017-7298 allows an attacker to execute cross-site scripting (XSS) attacks through the Course summary filter on the Add a new course page in Moodle.
2
Who is affected by CVE-2017-7298?
CVE-2017-7298 affects users running Moodle version 3.2.2 and potentially other versions in the 3.2 series.
3
How can I mitigate CVE-2017-7298?
To mitigate CVE-2017-7298, upgrade to a patched version of Moodle that addresses this XSS vulnerability.
4
What is the severity of CVE-2017-7298?
CVE-2017-7298 is categorized as a medium severity XSS vulnerability that could be exploited to compromise user sessions.
5
Is there a specific version of Moodle to avoid due to CVE-2017-7298?
Yes, avoid using Moodle version 3.2.2 as it contains the CVE-2017-7298 vulnerability.