CVE-2013-4523
Moodle <2.2.11, <2.3.10, <2.4.7, <2.5.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.
Scores
EPSS
0.0021
EPSS Percentile
43.1%
Details
CWE
CWE-79
Status
published
Products (50)
moodle/moodle
< 2.2.11
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 40 more
Published
Nov 26, 2013
Tracked Since
Feb 18, 2026