Description
A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.
Remediation
References
Related Vulnerabilities
WordPress Plugin About Author Box Cross-Site Scripting (1.0.1)
PHP Out-of-bounds Read Vulnerability (CVE-2016-6294)
PHP Deserialization of Untrusted Data Vulnerability (CVE-2007-1701)
Dotclear Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-7902)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5014)