The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moodle/moodle(Packagist) | 0 | 3.9.19 | N/A |
| moodle/moodle(Packagist) | 3.10.0 | 3.11.12 | N/A |
| moodle/moodle(Packagist) | 4.0.0-beta | 4.0.6 | N/A |
| moodle/moodle(Packagist) | 4.1.0-beta | 4.1.1 | N/A |
CVSS Metrics