Description In Moodle 3.x, there is XSS in the assignment submission page. Remediation References CVE-2017-2578 Related Vulnerabilities Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33938) XWiki Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') Vulnerability (CVE-2022-41928) Frontaccounting Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3740) MySQL CVE-2022-21370 Vulnerability (CVE-2022-21370) WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Cross-Site Scripting (1.2.3) Severity Medium Classification CVE-2017-2578 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities