CVE-2022-35651
Summary
| CVE | CVE-2022-35651 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-25 16:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Official Moodle git projects - moodle.git/search |
MISC |
git.moodle.org |
|
| [SECURITY] Fedora 35 Update: moodle-3.11.8-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: moodle-3.11.8-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: moodle-3.11.8-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: moodle-3.11.8-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 2106275 – (CVE-2022-35651, MSA-22-0017) CVE-2022-35651 moodle: Stored XSS and blind SSRF possible via SCORM track details |
MISC |
bugzilla.redhat.com |
|
| Moodle.org: MSA-22-0017: Stored XSS and blind SSRF possible via SCORM track details |
MISC |
moodle.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 282973 Fedora Security Update for moodle (FEDORA-2022-81ce74b2dd)
- 282974 Fedora Security Update for moodle (FEDORA-2022-7e7ce7df2e)