CVE-2021-47857
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
21/01/2026
Last modified:
21/01/2026
Description
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
7.20
Severity 3.x
HIGH



