3.5
CVSSv2

CVE-2014-3551

Published: 29/07/2014 Updated: 01/12/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle up to and including 2.3.11, 2.4.x prior to 2.4.11, 2.5.x prior to 2.5.7, 2.6.x prior to 2.6.4, and 2.7.x prior to 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.5.6

moodle moodle 2.5.0

moodle moodle 2.5.1

moodle moodle 2.5.2

moodle moodle 2.5.3

moodle moodle 2.5.4

moodle moodle 2.5.5

moodle moodle 2.3.1

moodle moodle 2.3.4

moodle moodle 2.3.6

moodle moodle 2.3.8

moodle moodle 2.3.9

moodle moodle 2.3.10

moodle moodle

moodle moodle 2.3.2

moodle moodle 2.3.3

moodle moodle 2.3.0

moodle moodle 2.3.5

moodle moodle 2.3.7

moodle moodle 2.7.0

moodle moodle 2.6.3

moodle moodle 2.6.1

moodle moodle 2.6.0

moodle moodle 2.6.2

moodle moodle 2.4.3

moodle moodle 2.4.5

moodle moodle 2.4.6

moodle moodle 2.4.7

moodle moodle 2.4.8

moodle moodle 2.4.9

moodle moodle 2.4.10

moodle moodle 2.4.0

moodle moodle 2.4.1

moodle moodle 2.4.2

moodle moodle 2.4.4

Github Repositories

CVE-2014-3551

CVE-2014-3551 Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2311, 24x before 2411, 25x before 257, 26x before 264, and 27x before 271 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric Grade field vulnerable /mo