Skip to main content

Improper Encoding or Escaping of Output

CVE-2021-40694

Severity Medium
Score 4.9/10

Summary

Insufficient escaping of the "LaTeX" preamble made it possible for site administrators to read files available to the HTTP server system account. This issue affects the moodle versions prior to 3.9.10, 3.10.x prior to 3.10.7, and 3.11.x prior to 3.11.3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • NONE

CWE-116 - Improper Encoding or Escaping of Output

The software prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Advisory Timeline

  • Published