CVE-2020-14320: XSS
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14320?
CVE-2020-14320 is a vulnerability in Moodle before versions 3.9.1, 3.8.4, and 3.7.7 that allows for a reflected XSS risk in the filter of the admin task log.
How does CVE-2020-14320 affect Moodle?
CVE-2020-14320 affects Moodle versions before 3.9.1, 3.8.4, and 3.7.7 by posing a risk of reflected XSS through the filter in the admin task log.
What is the severity of CVE-2020-14320?
The severity of CVE-2020-14320 is rated as medium with a CVSS score of 6.1.
How can I fix CVE-2020-14320?
To fix CVE-2020-14320, it is recommended to upgrade Moodle to version 3.9.1, 3.8.4, or 3.7.7, where the vulnerability is patched.
Where can I find more information about CVE-2020-14320?
More information about CVE-2020-14320 can be found at the following link: https://moodle.org/mod/forum/discuss.php?d=407392