CVE-2022-35651
MEDIUMMoodle 3.9.0-3.9.14 - Stored Cross-Site Scripting and Blind Server-Side Request Forgery in SCORM Track Details
Title source: llmDescription
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.
References (5)
Core 5
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2106275
Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=436458
Patch, Vendor Advisory x_refsource_misc
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71921
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/
Scores
CVSS v3
6.1
EPSS
0.0028
EPSS Percentile
51.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (7)
fedoraproject/fedora
35
fedoraproject/fedora
36
moodle/moodle
4.0.0 (6 CPE variants)
moodle/moodle
4.0.1
moodle/moodle
3.9 - 3.9.15Packagist
moodle/moodle
3.9.0 - 3.9.15
redhat/enterprise_linux
8.0
Published
Jul 25, 2022
Tracked Since
Feb 18, 2026