CVE-2012-3393: XSS
Published Jul 23, 2012
·Updated
Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.
Affected Software
11 affected components
Moodle moodle=2.1.0
Moodle moodle=2.1.1
Moodle moodle=2.1.2
Moodle moodle=2.1.3
Moodle moodle=2.1.4
Moodle moodle=2.1.5
Moodle moodle=2.1.6
Moodle moodle=2.2.0
Moodle moodle=2.2.1
Moodle moodle=2.2.2
Moodle moodle=2.2.3
Event History
Jul 23, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3393?
CVE-2012-3393 is classified as a moderate severity vulnerability that allows cross-site scripting (XSS) attacks.
2
How do I fix CVE-2012-3393?
To fix CVE-2012-3393, update Moodle to version 2.1.7, 2.2.4, or later.
3
What versions of Moodle are affected by CVE-2012-3393?
CVE-2012-3393 affects Moodle versions 2.1.0 through 2.1.6 and 2.2.0 through 2.2.3.
4
What types of attacks can be executed because of CVE-2012-3393?
CVE-2012-3393 allows remote authenticated administrators to inject arbitrary web script or HTML, leading to potential XSS attacks.
5
Who is at risk from CVE-2012-3393?
Authenticated administrators using vulnerable versions of Moodle are at risk from CVE-2012-3393.