CVE-2012-3393

Moodle - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

Scores

EPSS 0.0023
EPSS Percentile 45.7%

Classification

CWE
CWE-79
Status published

Affected Products (12)

moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
n/a/n/a

Timeline

Published Jul 23, 2012
Tracked Since Feb 18, 2026