5.4
CVSSv3

CVE-2021-36568

Published: 13/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 3.10.4

moodle moodle 3.9.7

moodle moodle 3.11.0

fedoraproject fedora 35

fedoraproject fedora 36