lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-11-24 11:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-9059
Mitre link : CVE-2014-9059
CVE.ORG link : CVE-2014-9059
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')