CVE-2008-3326
Publication date 25 July 2008
Last updated 24 July 2024
Ubuntu priority
Description
Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| moodle | ||
Notes
jdstrand
PoC at http://www.procheckup.com/Vulnerability_PR08-13.php reassigned priority to medium due to location of the vulnerability and the ease of exploitation for a non-privileged user (needs only blog access)
Patch details
| Package | Patch details |
|---|---|
| moodle |