MSA-19-0001: Manage groups capability is missing XSS risk flag

by Michael Hawkins.  

The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6,
Leer más...


MSA-18-0019: Boost theme - blog search GET parameter insufficiently filtered

by Michael Hawkins.  

The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.


...
Severity/Risk:Minor
Versions affected:3.5 to 3.5.1, 3.4 to 3.4.4, 3.3 to 3.3.7 and
Leer más...