GHSA-45ch-hxgr-vx8j

Suggest an improvement
Source
https://github.com/advisories/GHSA-45ch-hxgr-vx8j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-45ch-hxgr-vx8j/GHSA-45ch-hxgr-vx8j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-45ch-hxgr-vx8j
Aliases
  • CVE-2010-1618
Published
2022-05-13T01:13:09Z
Modified
2024-02-07T23:12:30.724580Z
Summary
phpCAS client library and Moodle Cross-site Scripting vulnerability
Details

Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.

Database specific
{
    "nvd_published_at": "2010-04-29T21:30:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-07T22:50:39Z"
}
References

Affected packages

Packagist / apereo/phpcas

Package

Name
apereo/phpcas
Purl
pkg:composer/apereo/phpcas

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.8.0
Fixed
1.8.12

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.9.0
Fixed
1.9.8