In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
{
"cpes": [
"cpe:2.3:a:moodle:moodle:3.11.0:-:*:*:*:*:*:*",
"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
],
"severity": "Medium"
}