{"id":"GHSA-j6c3-3c4w-qv8p","summary":"Moodle cross-site scripting (XSS) vulnerabilities","details":"Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.","aliases":["CVE-2013-7341"],"modified":"2024-12-03T06:08:31.322701Z","published":"2022-05-13T01:12:49Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-23T17:51:27Z","nvd_published_at":"2014-03-24T14:20:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7341"},{"type":"WEB","url":"https://github.com/flowplayer/flash/issues/121"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/98d135fea3006334093efa822205d4b2c3fd8ff9"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/9f2967e301d123d11625f3b6948e1ee538086791"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/c3cd5e1db9de4f1a634492d99990534e30518066"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/d65634044ebaa738f55bdec521beb42844d6916a"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2013-7341.yaml"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=256420"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2015-007"},{"type":"WEB","url":"http://flash.flowplayer.org/documentation/version-history.html"},{"type":"WEB","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43344"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/03/17/1"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.9"}]}],"versions":["v2.3.10","v2.3.11","v2.3.4","v2.3.5","v2.3.6","v2.3.7","v2.3.8","v2.3.9","v2.4.0","v2.4.0-rc1","v2.4.1","v2.4.2","v2.4.3","v2.4.4","v2.4.5","v2.4.6","v2.4.7","v2.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6c3-3c4w-qv8p/GHSA-j6c3-3c4w-qv8p.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.5"}]}],"versions":["v2.5.0","v2.5.1","v2.5.2","v2.5.3","v2.5.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6c3-3c4w-qv8p/GHSA-j6c3-3c4w-qv8p.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.2"}]}],"versions":["v2.6.0","v2.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6c3-3c4w-qv8p/GHSA-j6c3-3c4w-qv8p.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.14"}]}],"versions":["6.2.0","6.2.1","6.2.10","6.2.10-rc1","6.2.11","6.2.12","6.2.13","6.2.2","6.2.3","6.2.4","6.2.5","6.2.6","6.2.7","6.2.8","6.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6c3-3c4w-qv8p/GHSA-j6c3-3c4w-qv8p.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.3.1"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.1.0","7.2.0","7.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6c3-3c4w-qv8p/GHSA-j6c3-3c4w-qv8p.json"}}],"schema_version":"1.9.0"}