CVE-2020-25628: XSS
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25628?
CVE-2020-25628 has been classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2020-25628?
To fix CVE-2020-25628, upgrade your Moodle installation to versions 3.9.2, 3.8.5, 3.7.8, or 3.5.14, which include the necessary sanitization improvements.
Which versions of Moodle are affected by CVE-2020-25628?
CVE-2020-25628 affects Moodle versions 3.5 to 3.5.13, 3.7 to 3.7.7, 3.8 to 3.8.4, and 3.9 to 3.9.1, along with earlier unsupported versions.
What type of vulnerability is CVE-2020-25628?
CVE-2020-25628 is identified as a reflected cross-site scripting (XSS) vulnerability that requires additional input validation.
What potential risks does CVE-2020-25628 pose?
CVE-2020-25628 can potentially allow attackers to execute arbitrary scripts in the context of the user's web browser, compromising user data and session integrity.