CVE-2022-35653
Summary
| CVE | CVE-2022-35653 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-25 16:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: moodle-3.11.8-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 2106277 – (CVE-2022-35653, MSA-22-0019) CVE-2022-35653 moodle: LTI module reflected XSS risk - affecting unauthenticated users only |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 35 Update: moodle-3.11.8-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Moodle.org: MSA-22-0019: LTI module reflected XSS risk - affecting unauthenticated users only |
MISC |
moodle.org |
|
| [SECURITY] Fedora 36 Update: moodle-3.11.8-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: moodle-3.11.8-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Official Moodle git projects - moodle.git/search |
MISC |
git.moodle.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 282973 Fedora Security Update for moodle (FEDORA-2022-81ce74b2dd)
- 282974 Fedora Security Update for moodle (FEDORA-2022-7e7ce7df2e)