CVE-2021-36398: XSS
Published Mar 6, 2023
·Updated
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
Affected Software
1 affected component
Moodle moodle=3.11.0
Remediation
Patch Available
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Moodle vulnerability?
The vulnerability ID for this Moodle vulnerability is CVE-2021-36398.
2
What is the severity of CVE-2021-36398?
The severity of CVE-2021-36398 is medium with a CVSS score of 5.4.
3
What is the description of CVE-2021-36398?
CVE-2021-36398 is a vulnerability in Moodle where ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
4
Which version of Moodle is affected by CVE-2021-36398?
Moodle version 3.11.0 is affected by CVE-2021-36398.
5
Is there a fix available for CVE-2021-36398?
Yes, a fix is available for CVE-2021-36398. It is recommended to update to the latest version of Moodle to mitigate the vulnerability.