VDB
Sign up
MEDIUM

GHSA-45ch-hxgr-vx8j

phpCAS client library and Moodle Cross-site Scripting vulnerability

Quick fix

GHSA-45ch-hxgr-vx8j — apereo/phpcas: upgrade to the fixed version with the command below.

composer require apereo/phpcas:^1.1.0

Details

Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/apereo/phpcas
Introduced in: 0Fixed in: 1.1.0
Fixcomposer require apereo/phpcas:^1.1.0
Packagist/moodle/moodle
Introduced in: 1.8.0Fixed in: 1.8.12
Fixcomposer require moodle/moodle:^1.8.12
Packagist/moodle/moodle
Introduced in: 1.9.0Fixed in: 1.9.8
Fixcomposer require moodle/moodle:^1.9.8

References