CVE-2024-34006

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
Configurations

No configuration.

History

21 Nov 2024, 09:17

Type Values Removed Values Added
References () https://moodle.org/mod/forum/discuss.php?d=458395 - () https://moodle.org/mod/forum/discuss.php?d=458395 -

03 Jul 2024, 01:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

03 Jun 2024, 14:46

Type Values Removed Values Added
Summary
  • (es) El informe de registro del sitio requirió codificación adicional de las descripciones de eventos para garantizar que cualquier HTML en el contenido se muestre en texto plano en lugar de representarse.

31 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 21:15

Updated : 2024-11-21 09:17


NVD link : CVE-2024-34006

Mitre link : CVE-2024-34006

CVE.ORG link : CVE-2024-34006


JSON object : View

Products Affected

No product.

CWE
CWE-838

Inappropriate Encoding for Output Context