In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-13T21:06:51
Updated: 2024-08-04T01:01:57.457Z
Reserved: 2021-07-12T00:00:00
Link: CVE-2021-36568
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-13T22:15:08.793
Modified: 2024-11-21T06:13:50.130
Link: CVE-2021-36568
Redhat
No data.