Assignment Feedback worksheet - bug / exposure?

Assignment Feedback worksheet - bug / exposure?

by A K -
Number of replies: 0
A user tried to upload a Feedback worksheet (CSV file) for a Moodle Assignment.  Immediately after the upload stage, the page showing the records to be updated is truncated before the page display display completes.  Only the first few records are shown and the not the Confirm button, so the upload process can not be completed.

The user inspected the HTML and it shows that all the records were returned to the browser.  (They tried multiple browsers, with the same result).  The course just happens to be about HTML and Javascript and it appears that something in the feedback comments (HTML / Javascript?) is handled by the web browser in a way that terminates rendering of the page.  I do not have the uploaded file and have not been able to reproduce the problem with a test assignment, so far, but I am guessing that the feedback comments are not properly sanitised / escaped when being output to the browser prior to confirmation of upload so that part of the feedback is processed as HTML.  If this is the case, it suggests that there could be an exposure to code injection.

Is there anyone who has encountered this problem and / or can suggest a workaround (without limiting the content of the feedback comments)?  I haven't been able to find a bug report or forum discussion from quick searching.

Thanks for any insight.

Average of ratings: -