It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
2021-01-28T19:15:13.300
2024-11-21T05:46:05.590
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:H/Au:S/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 3.5.16 | Yes |
Application | moodle | moodle | < 3.8.7 | Yes |
Application | moodle | moodle | < 3.9.4 | Yes |
Application | moodle | moodle | < 3.10.1 | Yes |