CVE-2013-2244: XSS
Published Jul 26, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
Affected Software
6 affected components
Moodle moodle=2.4.0
Moodle moodle=2.4.1
Moodle moodle=2.4.2
Moodle moodle=2.4.3
Moodle moodle=2.4.4
Moodle moodle=2.5.0
Event History
Jul 26, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2244?
CVE-2013-2244 has a moderate severity rating due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2013-2244?
To fix CVE-2013-2244, upgrade to Moodle version 2.4.5 or 2.5.1 or later.
3
What software is affected by CVE-2013-2244?
CVE-2013-2244 affects Moodle versions 2.4.0 to 2.4.4 and 2.5.0.
4
What type of vulnerability is CVE-2013-2244?
CVE-2013-2244 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2013-2244 be exploited remotely?
Yes, CVE-2013-2244 can be exploited remotely by attackers to inject harmful scripts.