Description
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
Remediation
References
Related Vulnerabilities
Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-1856)
WordPress Plugin Bookings Cross-Site Scripting (1.8.2)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2006-0200)
Oracle Database Server CVE-2008-0345 Vulnerability (CVE-2008-0345)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-45038)