DSA-2262-1 moodle -- severalID: oval:org.secpod.oval:def:600570 | Date: (C)2011-07-06 (M)2022-10-10 |
Class: PATCH | Family: unix |
Several cross-site scripting and information disclosure issues have been fixed in Moodle, a course management system for online learning: * MSA-11-0002 Cross-site request forgery vulnerability in RSS block * MSA-11-0003 Cross-site scripting vulnerability in tag autocomplete * MSA-11-0008 IMS enterprise enrolment file may disclose sensitive information * MSA-11-0011 Multiple cross-site scripting problems in media filter * MSA-11-0015 Cross Site Scripting through URL encoding * MSA-11-0013 Group/Quiz permissions issue