CVE-2022-45151

MEDIUM

Moodle 3.11.0-3.11.10 - Stored Cross-Site Scripting in User Profile Fields

Title source: llm
STIX 2.1

Description

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
moodle/moodle 3.11 - 3.11.11Packagist
moodle/moodle 3.11.0 - 3.11.11
Published Nov 23, 2022
Tracked Since Feb 18, 2026