Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4183 to the following vulnerability: Name: CVE-2010-4183 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4183 Assigned: 20101105 Reference: CONFIRM: http://htmlpurifier.org/news/2010/0915-4.2.0-released Reference: CONFIRM: http://htmlpurifier.org/security/2010/css-quoting Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479. Both Moodle and Sahana contain embedded copies of HTMLPurifier. Current Moodle in Fedora (1.9.10) contains HTMLPurifier 4.2.0. Current Sahana in Fedora (0.6.3) contains HMTLPurifier 2.1.1 and would be vulnerable to this issue and possibly other issues (2.1.1 is a few years old now). Sahana should be updated to include the latest version of HTMLPurifier.
Created sahana tracking bugs for this issue Affects: fedora-all [bug 650560]