XSS Risk in Mustache Template Helpers in Moodle by Moodle
CVE-2022-40313
7.1HIGH
What is CVE-2022-40313?
The vulnerable aspect involves the recursive rendering of Mustache template helpers containing user input, which can lead to a potential XSS risk or result in a failure for the page to load correctly. This vulnerability can be exploited if an attacker provides malicious input, which may not be properly sanitized, causing unintended script execution in a user's browser.
Affected Version(s)
moodle 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions