Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-25631 - Vulnerability Database

Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-25631

Medium
Reference: CVE-2020-25631
Title: Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

A vulnerability was found in Moodle 3.9 to 3.9.1 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book39s chapter title which was not escaped on the quotAdd new chapterquot page. This is fixed in 3.9.2 3.8.5 and 3.7.8.