CVE-2012-2362: Moodle
Low severity, CVSS 2.6. EPSS: 1.2% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
Affected products
- Moodle Moodle: version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 1.9.4 only; version 1.9.5 only; version 1.9.6 only; …
Published 2012-07-21. Last modified 2026-06-16.