Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7298 - Vulnerability Database
Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7298
Medium
Reference:
CVE-2017-7298
Title:
Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Moodle 3.2.2 there is XSS in the Course summary filter of the quotAdd a new coursequot page as demonstrated by a crafted attribute of an SVG element.