Description
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.
Remediation
References
Related Vulnerabilities
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1614)
WordPress Plugin Admin username changer Unspecified Vulnerability (1.0)
Oracle Database Server CVE-2014-4291 Vulnerability (CVE-2014-4291)
Liferay DXP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-43762)