CVE-2022-40313
Description
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
CWE
- CWE-79 — CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected
- n/a / moodle — v=4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions [affected]
CVSS
- (none)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2128146 x_refsource_MISC
- https://moodle.org/mod/forum/discuss.php?d=438392 x_refsource_MISC
Source
cvelistV5-main/cves/2022/40xxx/CVE-2022-40313.json