Description
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
Remediation
References
Related Vulnerabilities
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Unspecified Vulnerability (5.1.2)
Ruby Improper Authentication Vulnerability (CVE-2009-0642)
WordPress Plugin Facebook for WooCommerce Cross-Site Request Forgery (1.9.14)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2355)