XSS Vulnerability in multiple XBlock Fields. Any platform that has deployed the XBlock will be impacted.
https://github.com/openedx/xblock-drag-and-drop-v2/commit/53c4482f9bb6d8c7ccdf5253bd82c84a222b2492
The fix is compatible with all Open edX releases newer than Lilac.
None.
https://github.com/openedx/xblock-drag-and-drop-v2/pull/295#issuecomment-1277693864
{
"cwe_ids": [
"CWE-79",
"CWE-80"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-02T22:26:22Z",
"nvd_published_at": "2022-11-28T21:15:00Z",
"severity": "HIGH"
}