Description
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.
Remediation
References
Related Vulnerabilities
Drupal CVE-2020-13665 Vulnerability (CVE-2020-13665)
WordPress Plugin Affiliate PRO Cross-Site Scripting (1.3.1)
Microsoft SQL Server Other Vulnerability (CVE-2000-1082)
WordPress 4.7.x Denial of Service Vulnerability (4.7 - 4.7.9)
WordPress Plugin Genie WP Favicon Cross-Site Request Forgery (0.5.2)