Description
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
Remediation
References
Related Vulnerabilities
Contao Improper Input Validation Vulnerability (CVE-2020-25768)
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4902)
Caddy Web Server Authentication Bypass by Spoofing Vulnerability (CVE-2023-50463)
WordPress Plugin Evarisk 'ajax.php' SQL Injection (5.1.3.6)
WordPress Plugin Podlove Podcast Publisher Multiple Vulnerabilities (2.3.15)