RULE(RULE ID:332465)

Rule General Information
Release Date: 2021-02-01
Rule Name: Moodle TeX Stored XSS Vulnerability (CVE-2021-20186)
Severity:
CVE ID:
Rule Protection Details
Description: It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://moodle.org/mod/forum/discuss.php?d=417170
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://moodle.org/security/