CVE-2023-28331: Moodle: xss risk when outputting database activity filter data
Published Mar 17, 2023
·Updated
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
Affected Software
16 affected componentsFixes available
redhat/moodle<4.1.2
4.1.2
redhat/moodle<4.0.7
4.0.7
redhat/moodle<3.11.13
3.11.13
redhat/moodle<3.9.20
3.9.20
composer/moodle/moodle<3.9.20
3.9.20
composer/moodle/moodle>=3.11.0<3.11.13
3.11.13
composer/moodle/moodle>=4.0.0<4.0.7
4.0.7
composer/moodle/moodle>=4.1.0<4.1.2
4.1.2
Moodle moodle>3.9.0<3.9.20
Moodle moodle>3.11.0<3.11.13
Moodle moodle>4.0.0<4.0.7
Moodle moodle=3.9.0
Moodle moodle=3.11.0
Moodle moodle=4.0.0
Moodle moodle=4.1.0
Moodle moodle=4.1.1
Remediation
Patch Available
Event History
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-28331.
2
What is the severity level of CVE-2023-28331?
The severity level of CVE-2023-28331 is medium, with a severity value of 6.1.
3
Which software versions are affected by CVE-2023-28331?
Moodle versions 3.9.0 to 3.9.20, 3.11.0 to 3.11.13, 4.0.0 to 4.0.7, 4.1.0, and 4.1.1 are affected by CVE-2023-28331.
4
What is the risk associated with CVE-2023-28331?
CVE-2023-28331 is an XSS vulnerability that can be exploited through the database auto-linking filter, posing a risk to the integrity of the content.
5
How can I mitigate or fix CVE-2023-28331?
To mitigate or fix CVE-2023-28331, it is recommended to apply the necessary additional sanitization to the content output by the database auto-linking filter.