Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Adam Roberts

Researcher fromNCC Group
#36080of 53,619
7.5Total CVSS
Vulnerabilities · 1
PT-2022-5145
7.5
2020-11-08
Moodle · Moodle · CVE-2022-40313
**Name of the Vulnerable Software and Affected Versions** Moodle (affected versions not specified) **Description** The issue is related to the recursive rendering of Mustache template helpers containing user input, which could result in a Cross-site Scripting risk or a page failing to load. This is due to insufficient cleaning of user data in the Mustache template helpers. An attacker could exploit this issue by creating a malicious link that, when clicked, would execute arbitrary HTML and script code in the user's browser within the context of the vulnerable website. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.