In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
3.8.0 | 3.8.4 |
moodle / moodle
|
3.7.0 | 3.7.7 |
moodle / moodle
|
3.9.0 | 3.9.0.x |