Description
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.
Remediation
References
Related Vulnerabilities
WordPress Plugin Chat-Support Board-WordPress Chat Privilege Escalation (3.3.8)
WordPress Plugin Super Simple Custom CSS Cross-Site Scripting (1.2)
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Cross-Site Scripting (5.8.0)
WordPress Plugin Widget Settings Importer/Exporter Cross-Site Scripting (1.5.3)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5688)