Description
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
Remediation
References
Related Vulnerabilities
PostgreSQL Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-1115)
WordPress Plugin UserPro-Community and User Profile Multiple Vulnerabilities (5.1.4)
Chamilo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-23127)
WordPress Plugin Custom Banners Cross-Site Scripting (1.2.2.2)