4.3
CVSSv2

CVE-2010-1619

Published: 29/04/2010 Updated: 01/12/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x prior to 1.8.12 and 1.9.x prior to 1.9.8, allows remote malicious users to inject arbitrary web script or HTML via crafted HTML entities.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 1.8.8

moodle moodle 1.8.7

moodle moodle 1.8.1

moodle moodle 1.8.3

moodle moodle 1.9.6

moodle moodle 1.8.5

moodle moodle 1.8.4

moodle moodle 1.9.3

moodle moodle 1.9.5

moodle moodle 1.8.2

moodle moodle 1.9.2

moodle moodle 1.9.1

moodle moodle 1.8.9

moodle moodle 1.8.6

moodle moodle 1.8.10

moodle moodle 1.8.11

moodle moodle 1.9.4

moodle moodle 1.9.7

Vendor Advisories

Debian Bug report logs - #586280 moodle: Cross Site Scripting vulnerability in blog/indexphp Package: moodle; Maintainer for moodle is (unknown); Reported by: Victor Martinez <vicm3@janusajuscoupnmx> Date: Fri, 18 Jun 2010 04:09:01 UTC Severity: grave Tags: patch, security Found in version moodle/182dfsg-3+lenny3 F ...
Debian Bug report logs - #585425 moodle: CVE-2010-1619 cross-site scripting in KSES HTML text cleaning library Package: moodle; Maintainer for moodle is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Thu, 10 Jun 2010 13:33:04 UTC Severity: grave Tags: patch, security Fixed in version moodle/199-1 Done: Toma ...
Several remote vulnerabilities have been discovered in Moodle, a course management system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1613 Moodle does not enable the Regenerate session id during login setting by default, which makes it easier for remote attackers to conduct session fixation atta ...