Description
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
Published: 2022-07-25
Score: 6.1 Medium
EPSS: 81.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-62wh-m4jr-233r Moodle LTI module reflected XSS risk
History

No history.

Subscriptions

Fedoraproject Fedora
Moodle Moodle
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-08-03T09:36:44.402Z

Reserved: 2022-07-12T00:00:00.000Z

Link: CVE-2022-35653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-25T16:15:08.520

Modified: 2024-11-21T07:11:26.603

Link: CVE-2022-35653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses