CVE-2010-2228
Moodle < 1.8.12 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
References (14)
Scores
EPSS
0.0061
EPSS Percentile
69.5%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
moodle/moodle
< 1.8.12
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 35 more
Timeline
Published
Jun 28, 2010
Tracked Since
Feb 18, 2026