From dba8d4496067bee2ce9dd23c42d55d223e71934a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 12 Apr 2025 02:54:53 +0000 Subject: [PATCH] Publish Advisories GHSA-62wv-866c-rh86 GHSA-86v9-gqh9-8268 GHSA-62wv-866c-rh86 --- .../GHSA-62wv-866c-rh86.json | 92 +++++++++++++++++++ .../GHSA-86v9-gqh9-8268.json | 52 ++++++++++- .../GHSA-62wv-866c-rh86.json | 41 --------- 3 files changed, 140 insertions(+), 45 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json (56%) delete mode 100644 advisories/unreviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json diff --git a/advisories/github-reviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json b/advisories/github-reviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json new file mode 100644 index 00000000000..aa12c931639 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62wv-866c-rh86", + "modified": "2025-04-12T02:53:38Z", + "published": "2022-05-13T01:13:15Z", + "aliases": [ + "CVE-2011-4297" + ], + "summary": "Moodle does not properly restrict comment capabilities", + "details": "comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.0.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.1.0" + }, + { + "fixed": "2.1.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4297" + }, + { + "type": "PACKAGE", + "url": "http://git.moodle.org" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=9da3c2efadcc5f56cb8adc19c67ed16be35780f3" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git;a=commit;h=9da3c2efadcc5f56cb8adc19c67ed16be35780f3" + }, + { + "type": "WEB", + "url": "http://moodle.org/mod/forum/discuss.php?d=182740" + }, + { + "type": "WEB", + "url": "http://openwall.com/lists/oss-security/2011/11/14/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:53:38Z", + "nvd_published_at": "2012-07-16T10:28:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json b/advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json rename to advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json index 42f771933fb..027cbb78b8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json +++ b/advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json @@ -1,19 +1,63 @@ { "schema_version": "1.4.0", "id": "GHSA-86v9-gqh9-8268", - "modified": "2025-04-11T03:59:16Z", + "modified": "2025-04-12T02:52:59Z", "published": "2022-05-13T01:13:09Z", "aliases": [ "CVE-2011-4286" ], + "summary": "Moodle vulnerable to Cross-site Scripting", "details": "Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.", "severity": [], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.9.0" + }, + { + "fixed": "1.9.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.0.2" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4286" }, + { + "type": "PACKAGE", + "url": "http://git.moodle.org" + }, { "type": "WEB", "url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=8f81bfd412c6b2e93a5b15711727d5cb7cc78336" @@ -36,8 +80,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:52:59Z", "nvd_published_at": "2012-07-16T10:28:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json b/advisories/unreviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json deleted file mode 100644 index 2cf97d32a6b..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-62wv-866c-rh86/GHSA-62wv-866c-rh86.json +++ /dev/null @@ -1,41 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-62wv-866c-rh86", - "modified": "2025-04-11T03:59:17Z", - "published": "2022-05-13T01:13:15Z", - "aliases": [ - "CVE-2011-4297" - ], - "details": "comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4297" - }, - { - "type": "WEB", - "url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=9da3c2efadcc5f56cb8adc19c67ed16be35780f3" - }, - { - "type": "WEB", - "url": "http://git.moodle.org/gw?p=moodle.git;a=commit;h=9da3c2efadcc5f56cb8adc19c67ed16be35780f3" - }, - { - "type": "WEB", - "url": "http://moodle.org/mod/forum/discuss.php?d=182740" - }, - { - "type": "WEB", - "url": "http://openwall.com/lists/oss-security/2011/11/14/1" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-07-16T10:28:00Z" - } -} \ No newline at end of file