Description
A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Ad Guru Lite Cross-Site Scripting (1.6.0)
WordPress Plugin Slideshow Gallery LITE Cross-Site Scripting (1.5.3.4)
Joomla! Core 1.0.x Unspecified Vulnerability (1.0.0 - 1.0.3)
MySQL CVE-2021-35622 Vulnerability (CVE-2021-35622)
Joomla Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-4104)