XBlock vulnerable to Cross-Site Scripting (XSS)
High severity
GitHub Reviewed
Published
Nov 28, 2022
in
openedx/xblock-drag-and-drop-v2
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 28, 2022
Published to the GitHub Advisory Database
Dec 2, 2022
Reviewed
Dec 2, 2022
Last updated
Jan 28, 2023
Impact
XSS Vulnerability in multiple XBlock Fields. Any platform that has deployed the XBlock will be impacted.
Patches
openedx/xblock-drag-and-drop-v2@53c4482
The fix is compatible with all Open edX releases newer than Lilac.
Workarounds
None.
References
openedx/xblock-drag-and-drop-v2#295 (comment)
References