CVE-2009-0502: XSS
Cross-site scripting (XSS) vulnerability in blocks/html/blockhtml.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0502?
CVE-2009-0502 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2009-0502?
To fix CVE-2009-0502, you should update to a patched version of Moodle or Snoopy that addresses the XSS vulnerability.
Which versions are affected by CVE-2009-0502?
CVE-2009-0502 affects Snoopy 1.2.3 and various versions of Moodle from 1.6 to 1.9 before their respective patches.
Can CVE-2009-0502 be exploited remotely?
Yes, CVE-2009-0502 can be exploited remotely by injecting malicious scripts through an HTML block.
What types of attacks are possible due to CVE-2009-0502?
CVE-2009-0502 allows attackers to perform cross-site scripting (XSS) attacks, which can lead to hijacking of user sessions or information theft.