PT-2022-27763 · Unknown · Drag/Drop Xblock

Feanil

·

Published

2022-11-28

·

Updated

2022-12-02

·

CVE-2022-46147

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drag and Drop XBlock v2 versions prior to 3.0.0
Description The issue affects the Drag and Drop XBlock v2, which implements a drag-and-drop style problem. It is vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.
Recommendations For versions prior to 3.0.0, update to version 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable XBlock Fields until the patch is applied. There are no known workarounds for this issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-46147
GHSA-QV6C-367R-3W6Q
PYSEC-2022-43175

Affected Products

Drag/Drop Xblock