Description
A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.
Remediation
References
Related Vulnerabilities
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.7)
WordPress Plugin Leaflet Maps Marker Pro Multiple Vulnerabilities (1.5.7)
MySQL CVE-2020-14765 Vulnerability (CVE-2020-14765)
WordPress Plugin Social Auto Poster-WordPress Scheduler & Marketing Arbitrary File Upload (5.3.14)
Dotclear Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-5083)