CVE-2021-20186

MEDIUM

Moodle <3.5.16, 3.8-3.8.7, 3.9-3.9.4, 3.10-3.10.1 - Stored Cross-Site Scripting in TeX Notation Filter

Title source: llm
STIX 2.1

Description

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=417170

Scores

CVSS v3 5.4
EPSS 0.0043
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
moodle/moodle < 3.5.16
moodle/moodle 3.10 - 3.10.1Packagist
Published Jan 28, 2021
Tracked Since Feb 18, 2026