← Back

CVE-2022-35653

Published: Jul 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

Affected (12)

1 product
Moodle
1 product
Fedora
1 product
Enterprise Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.11.0 to 3.11.8
From 3.9.0 to 3.9.15
Version 4.0.0
Version 4.0.0 beta
Version 4.0.0 rc1
Version 4.0.0 rc2
Version 4.0.0 rc3
Version 4.0.0 rc4
Version 4.0.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

Timeline

No history available yet.