CVE-2010-2230
Moodle < 1.8.12 - XSS
Title source: ruleDescription
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
References (16)
Scores
EPSS
0.0040
EPSS Percentile
60.1%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
moodle/moodle
< 1.8.12
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 35 more
Timeline
Published
Jun 28, 2010
Tracked Since
Feb 18, 2026