Record summary

CVE-2013-4341 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBMoodle 2.3.8/2.4.5 - Multiple VulnerabilitiesExploitDB exploitby Ciaran McNallyNot analyzed1 file
ExploitDB

PoC details
MetasploitMoodle Authenticated Spelling Binary RCEMetasploit exploitby Brandon Perry <bperry.volatile@gmail.com>Not analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

References

4