Lucene search

K
osvGoogleOSV:GHSA-WPFP-Q843-V772
HistoryNov 23, 2021 - 12:00 a.m.

Cross-site Scripting in moodle

2021-11-2300:00:51
Google
osv.dev
12
moodle
cross-site scripting
xss
vulnerability
version 3.9
version 3.10
version 3.11

EPSS

0.001

Percentile

36.6%

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

EPSS

0.001

Percentile

36.6%