A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8. References: https://moodle.org/mod/forum/discuss.php?d=410843
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1927276]
Created moodle tracking bugs for this issue: Affects: epel-7 [bug 1927287]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
External References: https://moodle.org/mod/forum/discuss.php?d=410843