header-logo
Suggest Exploit
vendor:
Moodle
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site Scripting and HTML Injection
79, 80
CWE
Product Name: Moodle
Affected Version From: 1.5
Affected Version To: 1.6.2001
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006

Moodle Multiple Input Validation Vulnerabilities

Moodle is reported prone to multiple input-validation vulnerabilities, including a cross-site scripting issue and an HTML injection issue, because the application fails to properly sanitize user-supplied input data. The cross-site scripting vulnerability is reported to affect version 1.6.1; the HTML-injection vulnerability affects version 1.5.

Mitigation:

Input validation should be used to ensure that user-supplied data is properly sanitized.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/21596/info

Moodle is reported prone to multiple input-validation vulnerabilities, including a cross-site scripting issue and an HTML injection issue, because the application fails to properly sanitize user-supplied input data. 

The cross-site scripting vulnerability is reported to affect version 1.6.1; the HTML-injection vulnerability affects version 1.5.

http://www.exmple.com/moodle/mod/forum/discuss.php?d=1&parent=2&navtail=<script >alert() < img src=& #106& #97& #118& #97& #115& #99& #114& #105& #112& #116& #58& #97& #108& #101& #114& #116& #40& #41>