GHSA-vvh5-7v3m-j3mj
GitHub Security Advisory
Moodle Unsanitized HTML in site log for config_log_created
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.3.0
(fixed in 4.3.4)
Packagist
moodle/moodle
Affected versions:
4.2.0
(fixed in 4.2.7)
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.1.10)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.