CVE-2022-30597: Medium severity moodle vulnerability
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Other sources
The description user field was not hidden when being set as a hidden user field.
Versions affected: 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions Versions fixed : 4.0.1, 3.11.7, 3.10.11 and 3.9.14
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30597?
The severity of CVE-2022-30597 is classified as moderate due to the exposure of user description fields that should be hidden.
How do I fix CVE-2022-30597?
To fix CVE-2022-30597, upgrade to Moodle versions 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
Which versions of Moodle are affected by CVE-2022-30597?
CVE-2022-30597 affects Moodle versions 4.0, 3.11, 3.10, 3.9, and earlier unsupported versions.
Is there a patch for CVE-2022-30597?
Yes, there are patches available for CVE-2022-30597 in the latest Moodle releases.
What does the vulnerability CVE-2022-30597 expose?
CVE-2022-30597 exposes the user description field, which is not properly hidden when set as a hidden user field.