CVE-2013-4341: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4341?
CVE-2013-4341 is classified as a medium-severity vulnerability due to the potential for cross-site scripting attacks that can affect users' sessions.
How do I fix CVE-2013-4341?
To mitigate CVE-2013-4341, upgrade your Moodle installation to version 2.2.12, 2.3.9, 2.4.6, or 2.5.2 or later.
What types of vulnerabilities are present in CVE-2013-4341?
CVE-2013-4341 contains multiple cross-site scripting (XSS) vulnerabilities that allow for the injection of arbitrary web script or HTML.
Which versions of Moodle are affected by CVE-2013-4341?
Moodle versions up to 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 are affected by CVE-2013-4341.
Who can exploit CVE-2013-4341?
Remote attackers can exploit CVE-2013-4341 by injecting malicious scripts through crafted blog links within an RSS feed.