Vulnerability Name: | CVE-2010-1619 (CCN-57549) | ||||||||||||||||||||||||
Assigned: | 2010-04-06 | ||||||||||||||||||||||||
Published: | 2010-04-06 | ||||||||||||||||||||||||
Updated: | 2020-12-01 | ||||||||||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML entities. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-1619 Source: SUSE Type: UNKNOWN SUSE-SR:2010:011 Source: CCN Type: MSA-10-0001 Vulnerability in KSES text cleaning Source: CCN Type: Moodle Web Site Moodle Security Announcements Source: CONFIRM Type: UNKNOWN http://moodle.org/security/ Source: DEBIAN Type: DSA-2115 moodle -- several vulnerabilities Source: CCN Type: OSVDB ID: 64324 Moodle weblib.php fix_non_standard_entities Function XSS Source: CCN Type: BID-39150 Moodle Prior to 1.9.8/1.8.12 Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2010-1107 Source: XF Type: UNKNOWN moodle-kses-xss(57549) Source: SUSE Type: SUSE-SR:2010:011 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |