First published: Fri Aug 06 2004(Updated: )
Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.2.1 | |
Moodle | =1.3.3 | |
Moodle | =1.3.2 | |
Moodle | =1.1.1 | |
Moodle | =1.3.1 | |
Moodle | =1.2.0 | |
Moodle | =1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1711 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2004-1711, you should upgrade to a version of Moodle that is later than 1.3, as the vulnerability has been addressed in these releases.
Moodle versions 1.1.1, 1.2.0, 1.2.1, and 1.3.0 to 1.3.3 are all affected by CVE-2004-1711.
CVE-2004-1711 can be exploited through cross-site scripting (XSS) attacks allowing remote attackers to inject arbitrary web scripts or HTML.
The impact of CVE-2004-1711 can result in unauthorized access to user sessions, data theft, or the execution of malicious scripts on users' browsers.