CVE-2013-7341
Publication date 24 March 2014
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
Status
Package | Ubuntu Release | Status |
---|---|---|
moodle | 25.04 plucky | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic |
Vulnerable
|
|
16.04 LTS xenial |
Vulnerable
|
|
14.04 LTS trusty | Not in release | |
References
Other references
- https://moodle.org/mod/forum/discuss.php?d=256420
- https://github.com/flowplayer/flash/issues/121
- http://openwall.com/lists/oss-security/2014/03/17/1
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43344
- http://flash.flowplayer.org/documentation/version-history.html
- https://www.cve.org/CVERecord?id=CVE-2013-7341