Description
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
Remediation
References
Related Vulnerabilities
WordPress Plugin EditorMonkey Remote File Upload (2.5)
WordPress Plugin Post Grid PHP Object Injection (2.0.11)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5489)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2023-6129)
WordPress Plugin Featured Content 'param' Parameter Cross-Site Scripting (0.0.1)