Loading HuntDB...

GHSA-vvh5-7v3m-j3mj

GitHub Security Advisory

Moodle Unsanitized HTML in site log for config_log_created

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

Affected Packages

Packagist moodle/moodle
Affected versions: 4.3.0 (fixed in 4.3.4)
Packagist moodle/moodle
Affected versions: 4.2.0 (fixed in 4.2.7)
Packagist moodle/moodle
Affected versions: 0 (fixed in 4.1.10)

Related CVEs

Key Information

GHSA ID
GHSA-vvh5-7v3m-j3mj
Published
May 31, 2024 9:30 PM
Last Modified
May 15, 2025 9:03 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.