Description
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
Remediation
References
Related Vulnerabilities
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7984)
WordPress Plugin Insert or Embed Articulate Content into WordPress Directory Traversal (4.2999)
IBM RTC Files or Directories Accessible to External Parties Vulnerability (CVE-2017-1602)
SharePoint CVE-2025-21348 Vulnerability (CVE-2025-21348)
WordPress Plugin 10WebAnalytics Cross-Site Request Forgery (1.2.8)