CVE-2009-0500: XSS
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0500?
CVE-2009-0500 is classified as a medium severity vulnerability due to its potential impact on user data and session security.
How do I fix CVE-2009-0500?
To fix CVE-2009-0500, upgrade your Moodle installation to version 1.6.9, 1.7.7, 1.8.8, or 1.9.4 or later.
What systems are affected by CVE-2009-0500?
CVE-2009-0500 affects Moodle versions prior to 1.6.9, 1.7.7, 1.8.8, and 1.9.4.
What type of vulnerability is CVE-2009-0500?
CVE-2009-0500 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
What impact could CVE-2009-0500 have on users?
CVE-2009-0500 could lead to session hijacking, defacement, or other malicious actions that compromise user security.