CVE-2012-3396
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en cohort/edit_form.php en Moodle v2.0.x anteriores a v2.0.10, v2.1.x anteriores a v2.1.7, v2.2.x anteriores a v2.2.4, y v2.3.x anteriores a v2.3.1, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del campo idnumber. NOTA: esta vulnerabilidad existe debido a una mala implementación de la solución para CVE-2012-2365.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-14 CVE Reserved
- 2012-07-23 CVE Published
- 2023-06-13 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34045 | X_refsource_confirm | |
http://openwall.com/lists/oss-security/2012/07/17/1 | Mailing List | |
http://secunia.com/advisories/49890 | Third Party Advisory | |
http://www.securityfocus.com/bid/54481 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76962 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.0 Search vendor "Moodle" for product "Moodle" and version "2.0.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.1 Search vendor "Moodle" for product "Moodle" and version "2.0.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.2 Search vendor "Moodle" for product "Moodle" and version "2.0.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.3 Search vendor "Moodle" for product "Moodle" and version "2.0.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.4 Search vendor "Moodle" for product "Moodle" and version "2.0.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.5 Search vendor "Moodle" for product "Moodle" and version "2.0.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.6 Search vendor "Moodle" for product "Moodle" and version "2.0.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.7 Search vendor "Moodle" for product "Moodle" and version "2.0.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.8 Search vendor "Moodle" for product "Moodle" and version "2.0.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.9 Search vendor "Moodle" for product "Moodle" and version "2.0.9" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.0 Search vendor "Moodle" for product "Moodle" and version "2.1.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.1 Search vendor "Moodle" for product "Moodle" and version "2.1.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.2 Search vendor "Moodle" for product "Moodle" and version "2.1.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.3 Search vendor "Moodle" for product "Moodle" and version "2.1.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.4 Search vendor "Moodle" for product "Moodle" and version "2.1.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.5 Search vendor "Moodle" for product "Moodle" and version "2.1.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.6 Search vendor "Moodle" for product "Moodle" and version "2.1.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.0 Search vendor "Moodle" for product "Moodle" and version "2.2.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.1 Search vendor "Moodle" for product "Moodle" and version "2.2.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.2 Search vendor "Moodle" for product "Moodle" and version "2.2.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.3 Search vendor "Moodle" for product "Moodle" and version "2.2.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.3.0 Search vendor "Moodle" for product "Moodle" and version "2.3.0" | - |
Affected
|