CVE-2021-20280: XSS
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Other sources
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks.
References:
https://moodle.org/mod/forum/discuss.php?d=419651
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20280?
CVE-2021-20280 is considered a moderate severity vulnerability due to its potential for stored XSS and blind SSRF risks.
How do I fix CVE-2021-20280?
To fix CVE-2021-20280, upgrade Moodle to version 3.10.2, 3.9.5, 3.8.8, or 3.5.17.
What versions of Moodle are affected by CVE-2021-20280?
CVE-2021-20280 affects Moodle versions prior to 3.10.2, 3.9.5, 3.8.8, and 3.5.17.
What types of attacks can CVE-2021-20280 facilitate?
CVE-2021-20280 can facilitate stored cross-site scripting (XSS) attacks and blind server-side request forgery (SSRF) attacks.
Is there a workaround for CVE-2021-20280?
No official workaround exists for CVE-2021-20280; the best mitigation is to update to a patched version.