Description
Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager SQL Injection (4.7.3)
WordPress Plugin Pricing Table by Supsystic Multiple Vulnerabilities (1.8.1)
OpenSSL Improper Input Validation Vulnerability (CVE-2015-1787)
Artifactory Improper Authentication Vulnerability (CVE-2023-42662)