← Back

CVE-2022-35651

nvd nist
Published: Jul 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

Affected (12)

1 product
Moodle
1 product
Enterprise Linux
1 product
Fedora
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.11.0 to 3.11.8
From 3.9.0 to 3.9.15
Version 4.0.0
Version 4.0.0 beta
Version 4.0.0 rc1
Version 4.0.0 rc2
Version 4.0.0 rc3
Version 4.0.0 rc4
Version 4.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36

Timeline

No history available yet.