It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
https://moodle.org/mod/forum/discuss.php?d=417170
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4109
Source: Mitre, NVD
Published: 2021-01-28
Updated: 2026-06-17
Base Score: 2.1
Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:N/A:N
Severity: Low
Base Score: 5.4
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity: Medium
EPSS: 0.00754