A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
2021-11-22T16:15:08.237
2024-11-21T06:29:26.040
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | ≤ 3.8.8 | Yes |
| Application | moodle | moodle | < 3.9.11 | Yes |
| Application | moodle | moodle | < 3.10.8 | Yes |
| Application | moodle | moodle | < 3.11.4 | Yes |
| Application | fedoraproject | extra_packages_for_enterprise_linux | 7.0 | Yes |
| Operating System | fedoraproject | fedora | 35 | Yes |