CVE-2008-5432

Moodle <1.6.8, <1.7.6, <1.8.7, <1.9.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

Scores

EPSS 0.0065
EPSS Percentile 70.5%

Classification

CWE
CWE-79
Status published

Affected Products (41)

moodle/moodle < 1.6.7
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 26 more

Timeline

Published Dec 11, 2008
Tracked Since Feb 18, 2026