A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.
2020-03-18T13:15:12.137
2024-11-21T04:27:36.467
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 3.5.9 | Yes |
Application | moodle | moodle | < 3.6.7 | Yes |
Application | moodle | moodle | ≤ 3.7.3 | Yes |