Описание
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
Релиз | Статус | Примечание |
---|---|---|
dapper | not-affected | |
devel | not-affected | 1.9.9.dfsg2-2 |
hardy | ignored | end of life |
jaunty | ignored | end of life |
karmic | ignored | end of life |
lucid | ignored | end of life |
maverick | ignored | end of life |
natty | not-affected | 1.9.9.dfsg2-2 |
oneiric | not-affected | 1.9.9.dfsg2-2 |
precise | not-affected | 1.9.9.dfsg2-2 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
Cross-site scripting (XSS) vulnerability in the MNET access-control in ...
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
EPSS
4.3 Medium
CVSS2