CVE-2012-2364: XSS
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2364?
CVE-2012-2364 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2012-2364?
To fix CVE-2012-2364, upgrade to Moodle version 2.0.9, 2.1.6, or 2.2.3 or later.
Who is affected by CVE-2012-2364?
Remote authenticated users of Moodle versions 2.0.x prior to 2.0.9, 2.1.x prior to 2.1.6, and 2.2.x prior to 2.2.3 are affected by CVE-2012-2364.
What types of attacks can CVE-2012-2364 enable?
CVE-2012-2364 can allow attackers to inject arbitrary web scripts or HTML through assignment submissions.
What versions of Moodle are vulnerable to CVE-2012-2364?
Moodle versions 2.0.0 through 2.0.8, 2.1.0 through 2.1.5, and 2.2.0 through 2.2.2 are vulnerable to CVE-2012-2364.