CVE-2021-20186
MEDIUMMoodle <3.5.16, 3.8-3.8.7, 3.9-3.9.4, 3.10-3.10.1 - Stored Cross-Site Scripting in TeX Notation Filter
Title source: llmDescription
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=417170
Scores
CVSS v3
5.4
EPSS
0.0043
EPSS Percentile
62.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
moodle/moodle
< 3.5.16
moodle/moodle
3.10 - 3.10.1Packagist
Published
Jan 28, 2021
Tracked Since
Feb 18, 2026