First published: Wed Oct 11 2023(Updated: )
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <4.3.0-rc2 | 4.3.0-rc2 |
Moodle Moodle | >=3.9.0<3.9.24 | |
Moodle Moodle | >=3.11.0<3.11.17 | |
Moodle Moodle | >=4.0.0<4.0.11 | |
Moodle Moodle | >=4.1.0<4.1.6 | |
Moodle Moodle | >=4.2.0<4.2.3 | |
redhat/moodle | <4.2.3 | 4.2.3 |
redhat/moodle | <4.1.6 | 4.1.6 |
redhat/moodle | <4.0.11 | 4.0.11 |
redhat/moodle | <3.11.17 | 3.11.17 |
redhat/moodle | <3.9.24 | 3.9.24 |
>=3.9.0<3.9.24 | ||
>=3.11.0<3.11.17 | ||
>=4.0.0<4.0.11 | ||
>=4.1.0<4.1.6 | ||
>=4.2.0<4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5541 is a vulnerability in the CSV grade import method in Moodle that allows for XSS attacks.
The severity of CVE-2023-5541 is medium, with a CVSS score of 6.1.
CVE-2023-5541 can be exploited by importing a spreadsheet with unsafe content, potentially leading to XSS attacks.
Moodle versions 3.9.0 to 3.9.24, 3.11.0 to 3.11.17, 4.0.0 to 4.0.11, 4.1.0 to 4.1.6, and 4.2.0 to 4.2.3 are affected by CVE-2023-5541.
To fix CVE-2023-5541, update Moodle to version 3.9.25, 3.11.18, 4.0.12, 4.1.7, or 4.2.4, or apply the corresponding patch provided by Red Hat.