CVE-2008-1225

WebCT Campus Edition 4.1.5.8 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Lupton · textwebappsphp
https://www.exploit-db.com/exploits/31337

Scores

EPSS 0.0051
EPSS Percentile 66.2%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

webct/webct

Timeline

Published Mar 10, 2008
Tracked Since Feb 18, 2026