Description
In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-4740 Vulnerability (CVE-2015-4740)
ownCloud Other Vulnerability (CVE-2012-5057)
WordPress Plugin WordPress Photo Gallery-Image Gallery Cross-Site Request Forgery (1.0.6)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-36396)
WordPress Plugin Import any XML or CSV File to WordPress Pro Arbitrary File Upload (4.1.0)