Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-30011

XSS vuln in Matching Question type

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not a bug
    • Icon: Minor Minor
    • None
    • 1.9.15
    • Questions
    • None
    • Any
    • MOODLE_19_STABLE

      JS can be inserted in the "Question" text boxes of the "Available choices" area, when editing/adding this question type. The JS will then execute whenever display.html is loaded (e.g in a quiz attempt).

            timhunt Tim Hunt
            binare E
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.