Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-14320 - Vulnerability Database
Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-14320
Medium
Reference:
CVE-2020-14320
Title:
Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Moodle before 3.9.1 3.8.4 and 3.7.7 the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.