CVE-2021-47857

All FrameworksMoodleCWE-79CVE-2021-47857

CVE-2021-47857

State: PUBLISHED · Published: 2026-01-21 · Updated: 2026-03-05 · Assigner: VulnCheck
Description
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/47xxx/CVE-2021-47857.json