CVE-2020-25627: XSS
Published Dec 9, 2020
·Updated
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
Affected Software
2 affected componentsFixes available
composer/moodle/moodle>=3.9<3.9.2
3.9.2
Moodle moodle>=3.9.0<3.9.2
Remediation
Patch Available
Event History
Dec 9, 2020
CVE Published
via MITRE·12:04 AM
Data Sourced
via MITRE·12:04 AM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-25627?
CVE-2020-25627 has a medium severity rating due to the potential for stored XSS vulnerabilities.
2
How do I fix CVE-2020-25627?
To fix CVE-2020-25627, update Moodle to version 3.9.2 or later.
3
Which versions are affected by CVE-2020-25627?
CVE-2020-25627 affects Moodle versions 3.9 to 3.9.1.
4
What type of vulnerability is CVE-2020-25627?
CVE-2020-25627 is a stored cross-site scripting (XSS) vulnerability.
5
What product does CVE-2020-25627 impact?
CVE-2020-25627 impacts the Moodle learning management system.