Description
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
Remediation
References
Related Vulnerabilities
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.2.7)
WordPress Plugin WooCommerce Security Bypass (2.1.7)
WordPress Plugin Advanced Woo Search Information Disclosure (1.99)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-2138)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19355)