PT-2022-8585 · Moodle+1 · Moodle+1

Cid Da Costa

·

Published

2020-01-14

·

Updated

2024-03-06

·

CVE-2020-1691

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle version 3.8
Description The issue concerns stored cross-site scripting. In Moodle, messages required extra sanitizing before updating the conversation overview to prevent this risk.
Recommendations For Moodle version 3.8, ensure that messages are properly sanitized before updating the conversation overview to prevent stored cross-site scripting.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1035
BIT-MOODLE-2020-1691
CVE-2020-1691
GHSA-CWHP-RQFR-8462

Affected Products

Alt Linux
Moodle