Medium severity5.4NVD Advisory· Published Sep 13, 2022· Updated Jun 17, 2026
CVE-2021-36568
CVE-2021-36568
Description
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | <= 3.9.7 | — |
moodle/moodlePackagist | >= 3.10.0, <= 3.10.4 | — |
moodle/moodlePackagist | >= 3.11.0, < 3.11.10 | 3.11.10 |
Affected products
8cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords2 versions
>= 3.9.7, < 3.9.8+ 1 more
- (no CPE)range: >= 3.9.7, < 3.9.8
- (no CPE)range: <= 3.9.7
Patches
Vulnerability mechanics
References
10- blog.hackingforce.com.br/en/cve-2021-36568/nvdExploitThird Party Advisory
- drive.google.com/drive/folders/1_fO4BKpmD3avGYHSzvIXWs5owqVYgB1snvdBroken LinkThird Party Advisory
- github.com/advisories/GHSA-fm6m-fg23-67jqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-36568ghsaADVISORY
- blog.hackingforce.com.br/en/cve-2021-36568ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ERQ3NHVOK4ZXT4MS4LBQ2ZJHTON3LIMWghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/PRI4ETMQ4DJR3TZUOOGPBQ32RBD5LNGCghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERQ3NHVOK4ZXT4MS4LBQ2ZJHTON3LIMW/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PRI4ETMQ4DJR3TZUOOGPBQ32RBD5LNGC/nvd
News mentions
0No linked articles in our index yet.