Candidate: CVE-2012-3393 PublicDate: 2012-07-23 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3393 http://openwall.com/lists/oss-security/2012/07/17/1 Description: Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=682203 Priority: low Discovered-by: Assigned-to: CVSS: Patches_moodle: upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=refs%2Fheads%2FMOODLE_22_STABLE&st=commit&s=MDL-33808 upstream_moodle: released (2.2.3.dfsg-2.1) hardy_moodle: ignored (reached end-of-life) lucid_moodle: not-affected natty_moodle: not-affected oneiric_moodle: not-affected precise_moodle: not-affected devel_moodle: not-affected (2.2.3.dfsg-2.1)