Lucene search

K
osvGoogleOSV:GHSA-H7H6-FWPV-GGVX
HistoryMay 24, 2022 - 5:44 p.m.

Moodle contains Stored XSS via ID number user profile field

2022-05-2417:44:37
Google
osv.dev
12
moodle
stored xss
id number
user profile
sanitizing
security risk
software

EPSS

0.001

Percentile

33.0%

The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

EPSS

0.001

Percentile

33.0%