Candidate: CVE-2018-14631 PublicDate: 2018-09-17 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14631 http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-62857 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14631 https://moodle.org/mod/forum/discuss.php?d=376025 Description: moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_moodle: upstream_moodle: needs-triage precise/esm_moodle: DNE trusty_moodle: ignored (reached end-of-life) trusty/esm_moodle: DNE (trusty was needs-triage) xenial_moodle: ignored (end of standard support, was needs-triage) bionic_moodle: needs-triage cosmic_moodle: ignored (reached end-of-life) disco_moodle: ignored (reached end-of-life) eoan_moodle: ignored (reached end-of-life) focal_moodle: DNE groovy_moodle: DNE hirsute_moodle: DNE impish_moodle: DNE jammy_moodle: DNE devel_moodle: DNE