PT-2022-27763 · Unknown · Drag/Drop Xblock
Feanil
·
Published
2022-11-28
·
Updated
2022-12-02
·
CVE-2022-46147
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Drag and Drop XBlock v2 versions prior to 3.0.0
Description
The issue affects the Drag and Drop XBlock v2, which implements a drag-and-drop style problem. It is vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.
Recommendations
For versions prior to 3.0.0, update to version 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable XBlock Fields until the patch is applied. There are no known workarounds for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drag/Drop Xblock