First published: Tue Sep 20 2022(Updated: )
Severity/Risk: Serious Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Adam Roberts, NCC Group CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2022-40313">CVE-2022-40313</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-68066">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-68066</a> Tracker issue: MDL-68066 Stored XSS and page denial of service risks due to recursive rendering in Mustache template helpers
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=4.0<=4.0.3>=3.11<=3.11.9>=3.9<=3.9.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2128146 is classified as serious.
Moodle versions affected by REDHAT-BUG-2128146 include 4.0 to 4.0.3, 3.11 to 3.11.9, and 3.9 to 3.9.16.
The fixed versions for REDHAT-BUG-2128146 are 4.0.4, 3.11.10, and 3.9.17.
To fix REDHAT-BUG-2128146, update your Moodle installation to the patched versions.
The vulnerability REDHAT-BUG-2128146 was reported by Adam Roberts from NCC Group.