CVE-2022-45151: XSS
MSA-22-0031: Stored XSS possible in some "social" user profile fields
The "social" user profile field type performed insufficient escaping on some fields, resulting in a stored XSS risk.
Versions affected: 4.0 to 4.0.4 and 3.11 to 3.11.10 Versions fixed: 4.0.5 and 3.11.11
Other sources
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.5Patch MSA-22-0031 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.11.11Patch MSA-22-0031
Event History
Frequently Asked Questions
What is CVE-2022-45151?
CVE-2022-45151 is a stored-XSS vulnerability in Moodle.
What is the severity of CVE-2022-45151?
CVE-2022-45151 has a severity rating of 5.4 (medium).
How does CVE-2022-45151 affect Moodle?
CVE-2022-45151 affects Moodle versions 3.11.0 to 3.11.11, and 4.0.0 to 4.0.5.
How can an attacker exploit CVE-2022-45151?
An attacker can exploit CVE-2022-45151 by injecting and executing arbitrary HTML and script code in a user's browser.
How to fix CVE-2022-45151?
To fix CVE-2022-45151, update Moodle to version 3.11.11 or 4.0.5, depending on the affected version.