CVE-2010-1619
Moodle < 1.8.12 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML entities.
Scores
EPSS
0.0025
EPSS Percentile
48.5%
Classification
CWE
CWE-79
Status
published
Affected Products (20)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 5 more
Timeline
Published
Apr 29, 2010
Tracked Since
Feb 18, 2026