CVE-2021-36399: XSS
Published Mar 6, 2023
·Updated
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
Affected Software
1 affected component
Moodle moodle=3.11.0
Remediation
Patch Available
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-36399?
CVE-2021-36399 is a vulnerability in Moodle where ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
2
What is the severity of CVE-2021-36399?
The severity of CVE-2021-36399 is medium, with a CVSS score of 5.4.
3
How does CVE-2021-36399 affect Moodle?
CVE-2021-36399 affects Moodle versions 3.11.0, allowing for a stored XSS risk in the quiz override screens.
4
How can I fix CVE-2021-36399 in Moodle?
To fix CVE-2021-36399 in Moodle, it is recommended to update to the latest version, which includes the necessary sanitization to prevent the stored XSS risk.
5
Where can I find more information about CVE-2021-36399?
You can find more information about CVE-2021-36399 in the Moodle forum discussion: https://moodle.org/mod/forum/discuss.php?d=424805