First published: Tue May 10 2022(Updated: )
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.9<3.9.14 | 3.9.14 |
composer/moodle/moodle | >=3.10<3.10.11 | 3.10.11 |
composer/moodle/moodle | >=3.11<3.11.7 | 3.11.7 |
composer/moodle/moodle | >=4.0<4.0.1 | 4.0.1 |
redhat/moodle | <4.0.1 | 4.0.1 |
redhat/moodle | <3.11.7 | 3.11.7 |
redhat/moodle | <3.10.11 | 3.10.11 |
redhat/moodle | <3.9.14 | 3.9.14 |
Moodle | >=3.9<3.9.14 | |
Moodle | >=3.10<3.10.11 | |
Moodle | >=3.11<3.11.7 | |
Moodle | =4.0.0 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Fedora | =34 | |
Red Hat Fedora | =35 | |
Red Hat Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30596 has a medium severity rating due to the potential for stored XSS attacks.
To fix CVE-2022-30596, update your Moodle installation to versions 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
CVE-2022-30596 affects Moodle versions 3.9.x up to 3.9.14, 3.10.x up to 3.10.11, 3.11.x up to 3.11.7, and 4.0.0.
CVE-2022-30596 is a remote vulnerability since it can be exploited through the web interface without direct system access.
Yes, CVE-2022-30596 affects Moodle installations on Red Hat versions up to 3.9.14, 3.10.11, 3.11.7, and 4.0.1.