CVE-2011-4307: XSS
Published Jul 11, 2012
·Updated
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
Affected Software
7 affected components
Moodle moodle=2.0.2
Moodle moodle=2.0.1
Moodle moodle=2.0.4
Moodle moodle=2.0.3
Moodle moodle=2.1.1
Moodle moodle=2.0.0
Moodle moodle=2.1.0
Event History
Jul 11, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4307?
CVE-2011-4307 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2011-4307?
To remediate CVE-2011-4307, upgrade Moodle to version 2.0.5 or 2.1.2 or later.
3
Which versions of Moodle are affected by CVE-2011-4307?
CVE-2011-4307 affects Moodle versions 2.0.x before 2.0.5 and 2.1.x before 2.1.2.
4
What type of vulnerability is CVE-2011-4307?
CVE-2011-4307 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2011-4307 allow attackers to compromise my Moodle site?
Yes, CVE-2011-4307 can allow remote attackers to inject arbitrary web script or HTML, potentially compromising your Moodle site.