Total vulnerabilities in the database
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
Software | From | Fixed in |
---|---|---|
moodle / moodle | 3.8.0 | 3.8.4 |
moodle / moodle | 3.7.0 | 3.7.7 |
moodle / moodle | 3.9.0 | 3.9.0.x |