CVE-2022-30596: XSS
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Other sources
ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Versions affected: 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions Versions fixed: 4.0.1, 3.11.7, 3.10.11 and 3.9.14.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30596?
CVE-2022-30596 has a medium severity rating due to the potential for stored XSS attacks.
How do I fix CVE-2022-30596?
To fix CVE-2022-30596, update your Moodle installation to versions 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
What versions of Moodle are affected by CVE-2022-30596?
CVE-2022-30596 affects Moodle versions 3.9.x up to 3.9.14, 3.10.x up to 3.10.11, 3.11.x up to 3.11.7, and 4.0.0.
Is CVE-2022-30596 a local or remote vulnerability?
CVE-2022-30596 is a remote vulnerability since it can be exploited through the web interface without direct system access.
Does CVE-2022-30596 affect Moodle installations on Red Hat?
Yes, CVE-2022-30596 affects Moodle installations on Red Hat versions up to 3.9.14, 3.10.11, 3.11.7, and 4.0.1.