Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in Moodle. Insufficient escaping of the username on the password reset page allowed a minor cross-site scripting (XSS) risk if an unauthenticated user was tricked into opening a crafted password reset link. The reporter states this did not affect authenticated user sessions; that disclaimer is reflected in the impact assessment here.