Vulnerability Details CVE-2020-25627
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 87.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-25627
-
cpe:2.3:a:moodle:moodle:3.9.0
-
cpe:2.3:a:moodle:moodle:3.9.1