Description
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Participants Database SQL Injection (1.9.5.5)
Joomla! Core 3.x.x Multiple Cross-Site Scripting Vulnerabilities (3.0.0 - 3.8.7)
Contao Improper Privilege Management Vulnerability (CVE-2021-37627)
PHP Other Vulnerability (CVE-2009-4017)
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (6.0.9)