ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
Severity/Risk: | Minor |
Versions affected: | 3.11 |
Versions fixed: | 3.11.1 |
Reported by: | Marina Glancy |
CVE identifier: | CVE-2021-36398 |
Changes (master): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71760 |
Tracker issue: | MDL-71760 Stored XSS in the web service token list via user ID number |
Read more https://moodle.org/mod/forum/discuss.php?d=424804&parent=1710823