Recommender before 1.3.1 allows XSS. It is possible for a learner to craft a fake resource to recommender, that includes script which could possibly steal credentials from staff if they are lured into viewing the recommended resource.
{
"nvd_published_at": "2019-08-09T16:15:00Z",
"github_reviewed_at": "2019-08-21T16:05:04Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true
}