CVE-2010-2230

medium
Published 2010-06-28 · Modified 2024-02-07
CVSS v3
CVSS v2
4.0
VIR risk
4.0

Description

The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2010-2230

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2010/1571

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2010/1530

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/40352

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/40248

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://cvs.moodle.org/moodle/lib/weblib.php?r1=1.970.2.171&r2=1.970.2.172

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://cvs.moodle.org/moodle/lib/weblib.php?r1=1.812.2.114&r2=1.812.2.115

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.0.4+dfsg-1
debian debianbullseyefixed3.0.4+dfsg-1
debian debianforkyfixed3.0.4+dfsg-1
debian debiansidfixed3.0.4+dfsg-1
debian debiantrixiefixed3.0.4+dfsg-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistmoodle/moodle<1.8.131.8.13
php Packagistmoodle/moodle>=1.9.0,<1.9.91.9.9

Application impact

VendorProductVersionsFixed
moodlemoodle{"endIncluding":"1.8.12"}
moodlemoodle1.1.1
moodlemoodle1.2.0
moodlemoodle1.2.1
moodlemoodle1.3.0
moodlemoodle1.3.1
moodlemoodle1.3.2
moodlemoodle1.3.3
moodlemoodle1.3.4
moodlemoodle1.4.1
moodlemoodle1.4.2
moodlemoodle1.4.3
moodlemoodle1.4.4
moodlemoodle1.4.5
moodlemoodle1.5
moodlemoodle1.5.0
moodlemoodle1.5.1
moodlemoodle1.5.2
moodlemoodle1.5.3
moodlemoodle1.6.0
moodlemoodle1.6.1
moodlemoodle1.6.2
moodlemoodle1.6.3
moodlemoodle1.6.4
moodlemoodle1.6.5
moodlemoodle1.6.6
moodlemoodle1.6.7
moodlemoodle1.6.8
moodlemoodle1.7.1
moodlemoodle1.7.2
moodlemoodle1.7.3
moodlemoodle1.7.4
moodlemoodle1.7.5
moodlemoodle1.7.6
moodlemoodle1.8.1
moodlemoodle1.8.2
moodlemoodle1.8.3
moodlemoodle1.8.4
moodlemoodle1.8.5
moodlemoodle1.8.6
moodlemoodle1.8.7
moodlemoodle1.8.8
moodlemoodle1.8.9
moodlemoodle1.8.10
moodlemoodle1.8.11
moodlemoodle1.9.1
moodlemoodle1.9.2
moodlemoodle1.9.3
moodlemoodle1.9.4
moodlemoodle1.9.5
moodlemoodle1.9.6
moodlemoodle1.9.7
moodlemoodle1.9.8

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.