#VU54987 Input validation error in Moodle - CVE-2021-36403
Published: July 19, 2021
Moodle
moodle.org
Description
The vulnerability allows a remote attacker to perform phishing attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing email notifications containing HTML. In some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.