Description
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Remediation
References
Related Vulnerabilities
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33511)
Joomla Improper Input Validation Vulnerability (CVE-2008-4105)
WordPress Plugin NEX-Forms-Ultimate Form builder SQL Injection (3.0)
WordPress Plugin Oleggo LiveStream Cross-Site Scripting (0.2.6)
WordPress Plugin WP Reroute Email Cross-Site Scripting (1.4.9)