Description
Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3045)
WordPress Plugin All-in-One WP Migration Security Bypass (7.14)
MySQL CVE-2013-1570 Vulnerability (CVE-2013-1570)
jQuery Validation Other Vulnerability (CVE-2022-31147)
WordPress Plugin Maps Widget for Google Maps-Google Maps Builder Open Redirect (4.0)