Description
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7467 | The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website. |
Github GHSA |
GHSA-xv72-6pgh-cjj8 | Moodle stored-XSS vulnerability in some "social" user profile fields |
References
History
Fri, 25 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-04-25T19:28:48.118Z
Reserved: 2022-11-11T00:00:00.000Z
Link: CVE-2022-45151
Updated: 2024-08-03T14:09:56.164Z
Status : Modified
Published: 2022-11-23T15:15:10.923
Modified: 2026-06-17T05:09:28.867
Link: CVE-2022-45151
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA