GHSA-86v9-gqh9-8268

Suggest an improvement
Source
https://github.com/advisories/GHSA-86v9-gqh9-8268
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-86v9-gqh9-8268
Aliases
  • CVE-2011-4286
Published
2022-05-13T01:13:09Z
Modified
2025-04-12T03:27:06.337851Z
Summary
Moodle vulnerable to Cross-site Scripting
Details

Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.

Database specific
{
    "github_reviewed_at": "2025-04-12T02:52:59Z",
    "nvd_published_at": "2012-07-16T10:28:00Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.9.0
Fixed
1.9.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json"

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86v9-gqh9-8268/GHSA-86v9-gqh9-8268.json"