Files
CVEs-PoC/2020/CVE-2020-25628.md
T
2024-05-25 21:48:12 +02:00

18 lines
719 B
Markdown

### [CVE-2020-25628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25628)
![](https://img.shields.io/static/v1?label=Product&message=Moodle&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%203.9%20to%203.9.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79&color=brighgreen)
### Description
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/luukverhoeven/luukverhoeven