PT-2021-2242 · Moodle+1 · Moodle+1

Kstpt

·

Published

2021-01-11

·

Updated

2024-03-06

·

CVE-2021-20183

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.10.1 Moodle versions prior to 4.0.0-beta
Description The issue is related to insufficient escaping of search queries in certain search inputs, which can lead to reflected Cross-site Scripting (XSS) attacks. This allows a remote attacker to conduct inter-site scripting attacks.
Recommendations For versions prior to 3.10.1, update to version 3.10.1 or later to resolve the issue. For versions prior to 4.0.0-beta, update to version 4.0.0-beta or later to resolve the issue. As a temporary workaround, consider restricting access to search inputs until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1050
ALT-PU-2021-1098
ALT-PU-2022-1641
BDU:2021-01194
BIT-MOODLE-2021-20183
CVE-2021-20183
GHSA-XHFX-RM8Q-C3XV

Affected Products

Alt Linux
Moodle