Description
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Remediation
References
Related Vulnerabilities
Joomla Other Vulnerability (CVE-2013-1453)
WordPress Plugin WP Super Cache PHP Code Injection (1.2)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Cross-Site Scripting (2.3.18)
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.12)
PHP Use of Uninitialized Resource Vulnerability (CVE-2019-11038)