PT-2012-3983 · Moodle · Moodle

Simon Coggins

·

Published

2012-07-21

·

Updated

2023-02-13

·

CVE-2012-2362

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 1.9.x through 1.9.17
Description A cross-site scripting issue exists due to insufficient input validation in the blog implementation. This allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to the "blog/index.php" endpoint, specifically when using Internet Explorer.
Recommendations For Moodle versions 1.9.x through 1.9.17, update to version 1.9.18 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2012-2362

Affected Products

Moodle