CVE-2023-5544, GHSA-j5xf-gv89-g422
packagist/moodle/moodle
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
All versions starting from 3.9.0 before 3.9.24, all versions starting from 3.11.0 before 3.11.17, all versions starting from 4.0.0 before 4.0.11, all versions starting from 4.1.0 before 4.1.6, all versions starting from 4.2.0 before 4.2.3
Upgrade to versions 3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 or above.
2023-11-10
source |