CVE-2024-33998
31.05.2024, 20:15
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 𝑥 < 4.1.10 |
| moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.7 |
| moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases