CVE-2020-25628

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/12/2020
Last modified:
08/12/2020

Description

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.14 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.7.0 (including) 3.7.8 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.8.0 (including) 3.8.5 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.9.0 (including) 3.9.2 (excluding)