Description
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2002-0364)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Remote Code Execution (5.0.0)
WordPress Plugin Akismet Cross-Site Scripting (3.1.4)
MySQL CVE-2017-10155 Vulnerability (CVE-2017-10155)
WordPress Plugin WordPress Landing Pages Unspecified Vulnerability (2.2.6)