6.1

CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 3.9.0 < 3.9.15
Moodle ≫ Moodle Version >= 3.11.0 < 3.11.8
Moodle ≫ Moodle Version 4.0.0 Update -
Moodle ≫ Moodle Version 4.0.0 Update beta
Moodle ≫ Moodle Version 4.0.0 Update rc1
Moodle ≫ Moodle Version 4.0.0 Update rc2
Moodle ≫ Moodle Version 4.0.0 Update rc3
Moodle ≫ Moodle Version 4.0.0 Update rc4
Moodle ≫ Moodle Version 4.0.1
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Redhat ≫ Enterprise Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.46% 0.904
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72299
Patch
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2106277
Third Party Advisory
Issue Tracking
https://moodle.org/mod/forum/discuss.php?d=436460
Patch
Vendor Advisory