XBlock vulnerable to Cross-Site Scripting (XSS)
High severity
GitHub Reviewed
Published
Nov 28, 2022
in
openedx/xblock-drag-and-drop-v2
•
Updated Nov 22, 2024
Description
Published by the National Vulnerability Database
Nov 28, 2022
Published to the GitHub Advisory Database
Dec 2, 2022
Reviewed
Dec 2, 2022
Last updated
Nov 22, 2024
Impact
XSS Vulnerability in multiple XBlock Fields. Any platform that has deployed the XBlock will be impacted.
Patches
openedx/xblock-drag-and-drop-v2@53c4482
The fix is compatible with all Open edX releases newer than Lilac.
Workarounds
None.
References
openedx/xblock-drag-and-drop-v2#295 (comment)
References