Vulnerability Description
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | < 3.5.16 |
Related Weaknesses (CWE)
References
- https://moodle.org/mod/forum/discuss.php?d=417170PatchVendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=417170PatchVendor Advisory
FAQ
What is CVE-2021-20186?
CVE-2021-20186 is a vulnerability with a CVSS score of 5.4 (MEDIUM). It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
How severe is CVE-2021-20186?
CVE-2021-20186 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20186?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.