Description
Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21336 Vulnerability (CVE-2022-21336)
WordPress Plugin Uploader 'uploadify.php' Arbitrary File Upload (1.0.4)
Oracle Application Server Other Vulnerability (CVE-2002-0559)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-1202)