In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2645.json"