Description
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Search Cross-Site Scripting (1.1.2)
Open Resty Off-by-one Error Vulnerability (CVE-2021-23017)
Claroline Other Vulnerability (CVE-2005-1374)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3170)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9410)