ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. This flaw affects versions 4.2 to 4.2.2, 4.1 to 4.1.5 and 4.0 to 4.0.10.
https://moodle.org/mod/forum/discuss.php?d=451587
Created moodle tracking bugs for this issue: Affects: epel-7 [bug 2244910] Affects: fedora-all [bug 2244912]