Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-3551 PoC — Moodle 跨站脚本漏洞

Source
Associated Vulnerability
Title:Moodle 跨站脚本漏洞 (CVE-2014-3551)
Description:Moodle是澳大利亚马丁-多基马(Martin Dougiamas)博士开发的一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle的advanced-grading实现中存在跨站脚本漏洞。远程攻击者可借助标题中特制的‘qualification’或‘rating’字段利用该漏洞注入任意Web脚本或HTML。以下版本受到影响:2.3.11及之前版本,2.4.11之前2.4.x版本,2.5.7之前2.5.x版本,2.6.4之前2.6.x版本,2.7版本。
Description
CVE-2014-3551
Readme
# CVE-2014-3551
Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

Grade field vulnerable
```
../mod/assign/view.php?id={id}&rownum=0
```


File Snapshot

[4.0K] /data/pocs/f38e45425252d3066f8bcd38ed6b47297534401a └── [ 428] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.