ATutor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2010-0971 - Vulnerability Database

ATutor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2010-0971

Low
Reference: CVE-2010-0971
Title: ATutor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users with Instructor privileges to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php the (3) Type and (4) Title fields in tools/groups/create_manual.php and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.