Description
A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stop User Enumeration User Enumeration (1.2.4)
Contao Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-37626)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4300)
Liferay Portal CVE-2011-1571 Vulnerability (CVE-2011-1571)
MediaWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-10959)