A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
2024-11-11T16:15:14.770
2025-04-23T21:26:17.000
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 4.1.12 | Yes |
Application | moodle | moodle | < 4.2.9 | Yes |
Application | moodle | moodle | < 4.3.6 | Yes |
Application | moodle | moodle | < 4.4.2 | Yes |