Improper Neutralization of Special Elements in Output Used by a Downstream Component in Moodle - CVE-2018-10891
Published: July 10, 2018 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
Affected software
Fedora
moodle
How to mitigate CVE-2018-10891
moodle - addressed in versions 3.1.13-1.el7, 3.1.13-2.el7, 3.3.7-1.fc27, 3.4.4-1.fc28