First published: Tue Nov 15 2022(Updated: )
MSA-22-0031: Stored XSS possible in some "social" user profile fields The "social" user profile field type performed insufficient escaping on some fields, resulting in a stored XSS risk. Versions affected: 4.0 to 4.0.4 and 3.11 to 3.11.10 Versions fixed: 4.0.5 and 3.11.11
Credit: bressers@elastic.co patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.11.0<3.11.11 | |
Moodle Moodle | >=4.0.0<4.0.5 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
composer/moodle/moodle | >=4.0<4.0.5 | 4.0.5 |
composer/moodle/moodle | >=3.11<3.11.11 | 3.11.11 |
redhat/moodle | <4.0.5 | 4.0.5 |
redhat/moodle | <3.11.11 | 3.11.11 |
>=3.11.0<3.11.11 | ||
>=4.0.0<4.0.5 | ||
=35 | ||
=36 | ||
=37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45151 is a stored-XSS vulnerability in Moodle.
CVE-2022-45151 has a severity rating of 5.4 (medium).
CVE-2022-45151 affects Moodle versions 3.11.0 to 3.11.11, and 4.0.0 to 4.0.5.
An attacker can exploit CVE-2022-45151 by injecting and executing arbitrary HTML and script code in a user's browser.
To fix CVE-2022-45151, update Moodle to version 3.11.11 or 4.0.5, depending on the affected version.