MSA-19-0026: Blind XSS reflected in some locations where user email is displayed

MSA-19-0026: Blind XSS reflected in some locations where user email is displayed

by Michael Hawkins -
Number of replies: 0

User emails required additional sanitizing to prevent blind XSS risk on some pages.


Severity/Risk: Minor
Versions affected: 3.7 to 3.7.2
Versions fixed: 3.7.3
Reported by: Yuri Zwaig
CVE identifier: CVE-2019-14881
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-66762
Tracker issue: MDL-66762 Blind XSS reflected in some locations where user email is displayed