Description
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
Remediation
References
Related Vulnerabilities
MySQL NULL Pointer Dereference Vulnerability (CVE-2020-1971)
Python Files or Directories Accessible to External Parties Vulnerability (CVE-2019-13404)
WordPress Plugin Booster for WooCommerce Multiple Cross-Site Scripting Vulnerabilities (5.4.8)
WordPress Cross-Site Scripting Vulnerability (0.70 - 3.7.11)