What the vulnerability does

01Description

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

Key dates

02Disclosure timeline

November 19, 2020 CVE published
August 4, 2024 Record updated