A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2021515 | Issue Tracking Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=429097 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fedora
Published: 2021-11-22T15:59:46
Updated: 2021-11-22T15:59:46
Reserved: 2021-11-09T00:00:00
Link: CVE-2021-43558
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-11-22T16:15:08.237
Modified: 2022-12-21T15:01:19.963
Link: CVE-2021-43558
JSON object: View
Redhat Information
No data.
CWE