CVE-2013-4341

Moodle < 2.2.11 - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

Exploits (2)

exploitdb WORKING POC
by Ciaran McNally · textwebappsphp
https://www.exploit-db.com/exploits/28174
metasploit WORKING POC EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/moodle_spelling_binary_rce.rb

References (3)

Core 3

Scores

EPSS 0.0973
EPSS Percentile 93.0%

Details

CWE
CWE-79
Status published
Products (18)
moodle/moodle 2.3.0
moodle/moodle 2.3.1
moodle/moodle 2.3.2
moodle/moodle 2.3.3
moodle/moodle 2.3.4
moodle/moodle 2.3.5
moodle/moodle 2.3.6
moodle/moodle 2.3.7
moodle/moodle 2.3.8
moodle/moodle 2.4.0
... and 8 more
Published Sep 16, 2013
Tracked Since Feb 18, 2026