Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-02-10T02:00:00

Updated: 2009-04-01T09:00:00

Reserved: 2009-02-09T00:00:00


Link: CVE-2009-0502

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-02-10T02:30:00.563

Modified: 2020-12-01T14:43:53.067


Link: CVE-2009-0502

JSON object: View

cve-icon Redhat Information

No data.

CWE