CVE-2011-4591: XSS
Cross-site scripting (XSS) vulnerability in the printobject function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4591?
CVE-2011-4591 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2011-4591?
To fix CVE-2011-4591, upgrade Moodle to version 2.0.6 or later and 2.1.3 or later.
What software versions are affected by CVE-2011-4591?
CVE-2011-4591 affects Moodle versions 2.0.0 through 2.0.5 and 2.1.0 through 2.1.2.
What type of attack does CVE-2011-4591 enable?
CVE-2011-4591 enables attackers to perform cross-site scripting (XSS) attacks by injecting malicious scripts.
Is enabling developer debugging script safe regarding CVE-2011-4591?
Enabling developer debugging scripts can expose your application to CVE-2011-4591, thus it is recommended to disable it.