Description
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7258 | A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages. |
Github GHSA |
GHSA-6gx2-g773-hv9h | Moodle reflected cross-site scripting vulnerability in policy tool |
References
History
Fri, 25 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-04-25T19:29:24.937Z
Reserved: 2022-11-11T00:00:00.000Z
Link: CVE-2022-45150
Updated: 2024-08-03T14:09:56.397Z
Status : Modified
Published: 2022-11-23T15:15:10.863
Modified: 2025-04-25T20:15:36.067
Link: CVE-2022-45150
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA