PT-2020-16140 · Moodle+1 · Moodle+1

Degrangem

·

Published

2020-10-15

·

Updated

2024-03-06

·

CVE-2020-25631

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 3.7 through 3.7.7 Moodle versions 3.8 through 3.8.4 Moodle versions 3.9 through 3.9.1
Description A vulnerability was found in Moodle where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page.
Recommendations For versions 3.7 through 3.7.7, update to version 3.7.8. For versions 3.8 through 3.8.4, update to version 3.8.5. For versions 3.9 through 3.9.1, update to version 3.9.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3059
ALT-PU-2020-3289
ALT-PU-2022-1641
BIT-MOODLE-2020-25631
CVE-2020-25631
GHSA-4W4J-9533-82QG

Affected Products

Alt Linux
Moodle