CVE-2021-36402

Moodle Improper Input Validation vulnerability in packagist/moodle/moodle

Identifiers

CVE-2021-36402, GHSA-gv8f-43pg-c5qw

Package Slug

packagist/moodle/moodle

Vulnerability

Moodle Improper Input Validation vulnerability

Description

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

Affected Versions

All versions before 3.9.8, all versions starting from 3.10.0 before 3.10.5, all versions starting from 3.11.0-beta before 3.11.1

Solution

Upgrade to versions 3.9.8, 3.10.5, 3.11.1 or above.

Last Modified

2023-03-08

source