Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw was found in Moodle. Insufficient escaping of the username on the password reset page allowed a minor cross-site scripting (XSS) risk if an unauthenticated user was tricked into opening a crafted password reset link. The reporter states this did not affect authenticated user sessions; that disclaimer is reflected in the impact assessment here.