In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moodle/moodle(Packagist) | 3.9 | 3.9.1 | N/A |
| moodle/moodle(Packagist) | 3.8 | 3.8.4 | N/A |
| moodle/moodle(Packagist) | 3.7 | 3.7.7 | N/A |
CVSS Metrics