CVE-2013-4525: XSS
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responsestable.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4525?
CVE-2013-4525 is classified as a medium severity vulnerability due to its ability to allow XSS attacks.
How do I fix CVE-2013-4525?
To fix CVE-2013-4525, update to Moodle version 2.3.10, 2.4.7, or 2.5.3 or later.
Who is affected by CVE-2013-4525?
CVE-2013-4525 affects all Moodle versions from 2.2.11 up to but not including 2.5.3.
What kind of attack is possible due to CVE-2013-4525?
CVE-2013-4525 allows remote authenticated users to inject arbitrary web script or HTML into Moodle.
Is CVE-2013-4525 still a risk if I am using a supported version of Moodle?
If you are using a supported version of Moodle, CVE-2013-4525 is not a risk as it has been patched.