CVE-2022-45150

MEDIUM

Moodle 3.9.0-3.9.17 - Reflected Cross-Site Scripting in Policy Tool

Title source: llm
STIX 2.1

Description

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.

Scores

CVSS v3 6.1
EPSS 0.0071
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
moodle/moodle 3.9 - 3.9.18Packagist
moodle/moodle 3.9.0 - 3.9.18
Published Nov 23, 2022
Tracked Since Feb 18, 2026