Loading HuntDB...

GHSA-wpfp-q843-v772

GitHub Security Advisory

Cross-site Scripting in moodle

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

Affected Packages

Packagist moodle/moodle
Affected versions: 3.11.0 (fixed in 3.11.4)
Packagist moodle/moodle
Affected versions: 3.10.0 (fixed in 3.10.8)
Packagist moodle/moodle
Affected versions: 3.9.0 (fixed in 3.9.11)

Related CVEs

Key Information

GHSA ID
GHSA-wpfp-q843-v772
Published
November 23, 2021 12:00 AM
Last Modified
June 17, 2022 1:13 AM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.