Release date:
Updated on:
Affected Systems:
Moodle 2.5.x
Moodle 2.3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63898
CVE (CAN) ID: CVE-2013-4523
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
Moodle does not properly filter some input in the messaging system. Successful exploitation of this vulnerability can cause arbitrary HTML and script code to be executed in the user browser session of the affected site.
<* Source: Panagiotis Petasis
Link: http://secunia.com/advisories/55835
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://moodle.org/
Moodle (MSA-13-0037, MSA-13-0038, MSA-13-0039, MSA-13-0040 ):
Https://moodle.org/mod/forum/discuss.php? D = 244480
Https://moodle.org/mod/forum/discuss.php? D = 244481
Https://moodle.org/mod/forum/discuss.php? D = 244482
Https://moodle.org/mod/forum/discuss.php? D = 244483