PT-2022-4074 · Moodle+2 · Moodle+2

Luuk Verhoeven

·

Published

2020-11-08

·

Updated

2024-05-04

·

CVE-2022-35653

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A reflected XSS issue was identified in the LTI module of Moodle due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim into following a specially crafted link and execute arbitrary HTML and script code in the user's browser in the context of the vulnerable website to steal potentially sensitive information, change the appearance of the web page, perform phishing, and drive-by-download attacks. This issue does not impact authenticated users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3235
ALT-PU-2022-2502
ALT-PU-2022-2553
BDU:2022-04908
BIT-MOODLE-2022-35653
CVE-2022-35653
GHSA-62WH-M4JR-233R

Affected Products

Alt Linux
Moodle
Red Os