Description
Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-2605 Vulnerability (CVE-2008-2605)
WordPress Plugin Powie's WHOIS Domain Check Cross-Site Scripting (0.9.31)
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.16)
WordPress Plugin Real WYSIWYG 'insert_file.php' Arbitrary File Upload (0.0.2)
WordPress Plugin Product Addons & Fields for WooCommerce Arbitrary File Upload (1.1)