Moodle 2.5.9 / 2.6.8 / 2.7.5 / 2.8.3 Cross Site Scripting

Moodle suffers from persistent cross site scripting vulnerabilities. Input passed to the POST parameters ‘config_title’ and ‘title’ thru index.php, are not properly sanitized allowing the attacker to execute HTML or JS code into user’s browser session on the affected site. Affected components: Blocks, Glossary, RSS and Tags.

Leave a Reply