A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-43558.json"