CVE-2011-4282: XSS
Published Jul 16, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the course-tags functionality in tag/coursetagsmore.php in Moodle 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sort or (2) show parameter.
Affected Software
3 affected componentsFixes available
Moodle moodle=2.0.1
Moodle moodle=2.0.0
composer/moodle/moodle>=2.0.0<2.0.2
2.0.2
Remediation
Event History
Jul 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:13 AM
Data Sourced
via GitHub·01:13 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4282?
CVE-2011-4282 is classified as a moderate severity vulnerability due to its ability to allow remote attackers to inject arbitrary web scripts.
2
How do I fix CVE-2011-4282?
To fix CVE-2011-4282, you should upgrade Moodle to version 2.0.2 or later.
3
Which versions of Moodle are affected by CVE-2011-4282?
CVE-2011-4282 affects Moodle versions 2.0.0 and 2.0.1.
4
What type of vulnerability is CVE-2011-4282?
CVE-2011-4282 is a cross-site scripting (XSS) vulnerability.
5
In which file does CVE-2011-4282 occur?
CVE-2011-4282 occurs in the course-tags functionality within the tag/coursetags_more.php file.