Lucene search

K
osvGoogleOSV:GHSA-PGCP-M69H-P2GR
HistoryMar 29, 2021 - 8:43 p.m.

Cross-site Scripting (XSS) in moodle

2021-03-2920:43:08
Google
osv.dev
16
cross-site scripting
moodle
javascript
content bank
vulnerability
version 3.9 to 3.9.2
fixed
version 3.9.3
version 3.10

EPSS

0.001

Percentile

46.9%

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

EPSS

0.001

Percentile

46.9%