A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
{ "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "nvd_published_at": "2018-07-10T18:29:00Z", "github_reviewed_at": "2023-07-20T23:32:15Z", "github_reviewed": true }