PT-2026-39472 · Moodle · Moodle Lms

Saud Alenazi

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2022-50943

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle LMS version 4.0
Description An issue allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Specifically, JavaScript code can be injected via the search field in the 'course/search.php' endpoint to execute arbitrary scripts in users' browsers and steal session cookies. This is a cross-site scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or escaping.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50943

Affected Products

Moodle Lms