← Vulnerability feed

Vulnerability record · CVE-2008-1502 · published 25 March 2008

CVE-2008-1502: Egroupware cross-site scripting vulnerability

Egroupware · Egroupware

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

4.3 CVSS 2.0 Medium EPSS 11% · top 4.4% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
42References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5 PatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
http://secunia.com/advisories/29491 Vendor Advisory
http://secunia.com/advisories/30073 Vendor Advisory
http://secunia.com/advisories/30986 Vendor Advisory
http://secunia.com/advisories/31017 Vendor Advisory
http://secunia.com/advisories/31018 Vendor Advisory
http://secunia.com/advisories/31167
http://secunia.com/advisories/32400 Vendor Advisory
http://secunia.com/advisories/32446 Vendor Advisory
http://www.debian.org/security/2008/dsa-1691 Patch
http://www.debian.org/security/2009/dsa-1871
http://www.egroupware.org/changelog
http://www.egroupware.org/viewvc/branches/1.4/phpgwapi/inc/class.kses.inc.php?r1=23625&r2=25110&pathrev=25110 Exploit
http://www.gentoo.org/security/en/glsa/glsa-200805-04.xml
http://www.openwall.com/lists/oss-security/2008/07/08/14
http://www.securityfocus.com/bid/28424 Patch
http://www.vupen.com/english/advisories/2008/0989/references Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/41435
https://usn.ubuntu.com/658-1/
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00331.html
http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5 PatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
http://secunia.com/advisories/29491 Vendor Advisory
http://secunia.com/advisories/30073 Vendor Advisory
http://secunia.com/advisories/30986 Vendor Advisory
http://secunia.com/advisories/31017 Vendor Advisory
http://secunia.com/advisories/31018 Vendor Advisory
http://secunia.com/advisories/31167
http://secunia.com/advisories/32400 Vendor Advisory
http://secunia.com/advisories/32446 Vendor Advisory
http://www.debian.org/security/2008/dsa-1691 Patch
http://www.debian.org/security/2009/dsa-1871
http://www.egroupware.org/changelog
http://www.egroupware.org/viewvc/branches/1.4/phpgwapi/inc/class.kses.inc.php?r1=23625&r2=25110&pathrev=25110 Exploit
http://www.gentoo.org/security/en/glsa/glsa-200805-04.xml
http://www.openwall.com/lists/oss-security/2008/07/08/14
http://www.securityfocus.com/bid/28424 Patch
http://www.vupen.com/english/advisories/2008/0989/references Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/41435

Track CVE-2008-1502 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-3809Moodle cross-site request forgery vulnerabilityA flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…EPSS 0.86%10.0CVE-2008-2041Egroupware code injection vulnerabilityMultiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write ac…EPSS 1.6%10.0CVE-2007-3154Egroupware vulnerabilityUnspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has …EPSS 1.9%10.0CVE-2007-3155Egroupware vulnerabilityUnspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from th…EPSS 1.8%10.0CVE-2006-4935Moodle improper input validation vulnerabilityThe Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.EPSS 1.5%10.0CVE-2006-4936Moodle improper input validation vulnerabilityMoodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote a…EPSS 1.5%10.0CVE-2005-2247Moodle vulnerabilityMultiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.EPSS 1.5%10.0CVE-2004-2233Moodle vulnerabilityUnknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2008-1502), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.