CVE-2012-3396: XSS
Cross-site scripting (XSS) vulnerability in cohort/editform.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3396?
The severity of CVE-2012-3396 is classified as a medium risk because it allows cross-site scripting (XSS) attacks affecting authenticated administrators.
How do I fix CVE-2012-3396?
To fix CVE-2012-3396, update Moodle to the latest recommended version, at least 2.0.10, 2.1.7, 2.2.4, or 2.3.1.
Who is affected by CVE-2012-3396?
CVE-2012-3396 affects remote authenticated administrators using Moodle versions prior to the fixed releases.
What impact does CVE-2012-3396 have on Moodle users?
CVE-2012-3396 allows remote authenticated administrators to inject arbitrary web scripts or HTML, potentially compromising data integrity.
When was CVE-2012-3396 disclosed?
CVE-2012-3396 was disclosed in July 2012.