git.moodle.orgConfirmation
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-41623 CVE-2013-4341
Moodle 2.3.8/2.4.5 - Multiple Vulnerabilities
Record summary
CVE-2013-4341 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMoodle 2.3.8/2.4.5 - Multiple VulnerabilitiesExploitDB exploitby Ciaran McNallyNot analyzed1 file
MetasploitMoodle Authenticated Spelling Binary RCEMetasploit exploitby Brandon Perry <bperry.volatile@gmail.com>Not analyzed1 file
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/164479/Moodle-Authenticated-Spelling-Binary-Remote-Code-Execution.html moodle.orgConfirmation
https://moodle.org/mod/forum/discuss.php?d=238399 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-4341