CVE-2022-40313: XSS
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an Cross-site Scripting risk or a page failing to load.
Other sources
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
— NVD
Severity/Risk: Serious Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Adam Roberts, NCC Group CVE identifier: CVE-2022-40313 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-68066 Tracker issue: MDL-68066 Stored XSS and page denial of service risks due to recursive rendering in Mustache template helpers
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.17 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.9.17
Event History
Frequently Asked Questions
What is CVE-2022-40313?
CVE-2022-40313 is a vulnerability that allows recursive rendering of Mustache template helpers containing user input, potentially resulting in an XSS risk or a page failing to load.
What is the severity of CVE-2022-40313?
The severity of CVE-2022-40313 is high with a severity value of 7.1.
Which software is affected by CVE-2022-40313?
The affected software includes Moodle versions 3.9.0 to 3.9.17, 3.11.0 to 3.11.10, and 4.0.0 to 4.0.4, as well as Fedora Project Extra Packages For Enterprise Linux 8.0, Fedora 35, and Fedora 36.
How can CVE-2022-40313 be fixed?
To fix CVE-2022-40313, users should update their Moodle software to a secure version and apply any necessary patches or updates provided by the vendor.
Where can I find more information about CVE-2022-40313?
More information about CVE-2022-40313 can be found on the Red Hat Security website, Moodle Git repository, and Bugzilla.