Description
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1975)
osTicket Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-14749)
WordPress Plugin Wordpress Uninstall Cross-Site Request Forgery (1.2.1)
WordPress Plugin Countdown Block Security Bypass (1.1.1)
WordPress Plugin Poll, Survey, Form & Quiz Maker by OpinionStage Unspecified Vulnerability (15.0.0)