CVE-2012-3389: XSS
Published Jul 23, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ltitypename or (2) ltitoolurl parameter.
Affected Software
5 affected components
Moodle moodle=2.2.0
Moodle moodle=2.2.1
Moodle moodle=2.2.2
Moodle moodle=2.2.3
Moodle moodle=2.3.0
Event History
Jul 23, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
Which Moodle versions need remediation?
Moodle 2.2.x installations earlier than 2.2.4 and Moodle 2.3.x installations earlier than 2.3.1 are affected. Other versions are not identified in the provided data.
2
What access and inputs does an attacker need?
An attacker can exploit the issue remotely without authentication by supplying script or HTML in the lti_typename or lti_toolurl parameter to mod/lti/typessettings.php. Successful exploitation can affect integrity through cross-site scripting.