CVE-2021-43558
Description
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
CWE
- CWE-79 — CWE-79
Affected
- n/a / moodle — v=moodle 3.11.4, moodle 3.10.8 and moodle 3.9.11 [affected]
CVSS
- (none)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2021515 x_refsource_MISC
- https://moodle.org/mod/forum/discuss.php?d=429097 x_refsource_MISC
Source
cvelistV5-main/cves/2021/43xxx/CVE-2021-43558.json