Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-04-29T21:00:00

Updated: 2024-08-07T01:28:42.949Z

Reserved: 2010-04-29T00:00:00

Link: CVE-2010-1618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-04-29T21:30:00.807

Modified: 2020-12-01T14:43:53.067

Link: CVE-2010-1618

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-03-27T00:00:00Z

Links: CVE-2010-1618 - Bugzilla