CVE-2022-45150: XSS
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.
Other sources
MSA-22-0030: Reflected XSS risk in policy tool
The return URL in the policy tool required extra sanitizing to prevent a reflected XSS risk.
Versions affected: 4.0 to 4.0.4, 3.11 to 3.11.10, 3.9 to 3.9.17 and earlier unsupported versions Versions fixed: 4.0.5, 3.11.11 and 3.9.18
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.18 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.9.18 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.9.18 - Compensating control
MSA-22-0030: Reflected XSS risk in Moodle policy tool—ensure the return URL in the policy tool is sufficiently sanitized to prevent reflected XSS.
Event History
Frequently Asked Questions
What is CVE-2022-45150?
CVE-2022-45150 is a reflected cross-site scripting vulnerability in Moodle.
How does CVE-2022-45150 occur?
CVE-2022-45150 occurs due to insufficient sanitization of user-supplied data in the policy tool of Moodle.
What is the severity of CVE-2022-45150?
The severity of CVE-2022-45150 is medium, with a severity value of 6.1.
Which versions of Moodle are affected by CVE-2022-45150?
Moodle versions 3.9.0 to 3.9.18, 3.11.0 to 3.11.11, and 4.0.0 to 4.0.5 are affected by CVE-2022-45150.
How can I fix CVE-2022-45150 in Moodle?
To fix CVE-2022-45150 in Moodle, you should upgrade to version 3.9.18, 3.11.11, or 4.0.5.