Vulnerability Name: | CVE-2012-2361 (CCN-75750) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2012-05-21 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2012-05-21 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2020-12-01 | ||||||||||||||||||||||||||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-2361 Source: CONFIRM Type: UNKNOWN http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31694 Source: CCN Type: MSA-12-0032 Cross-site scripting vulnerability in Web services Source: MLIST Type: UNKNOWN [oss-security] 20120523 Moodle security notifications public Source: CCN Type: SA49233 Moodle Multiple Vulnerabilities Source: CCN Type: OSVDB ID: 82068 Moodle admin/webservice/service.php name Parameter XSS Source: CCN Type: BID-53629 Moodle Multiple Information Disclosure and Security Bypass Vulnerabilities Source: XF Type: UNKNOWN moodle-service-xss(75750) | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |