Description
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.
Remediation
References
Related Vulnerabilities
Java Unspesificed Vulnerability (CVE-2019-2786)
qdPM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-26165)
MongoDb Other Vulnerability (CVE-2018-20802)
WordPress Plugin Easy2Map Photos Cross-Site Scripting (2.0.6)
WordPress Plugin CM Download Manager Cross-Site Scripting (2.7.0)