The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7467 | The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website. |
Github GHSA |
GHSA-xv72-6pgh-cjj8 | Moodle stored-XSS vulnerability in some "social" user profile fields |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-04-25T19:28:48.118Z
Reserved: 2022-11-11T00:00:00.000Z
Link: CVE-2022-45151
Updated: 2024-08-03T14:09:56.164Z
Status : Modified
Published: 2022-11-23T15:15:10.923
Modified: 2025-04-25T20:15:36.237
Link: CVE-2022-45151
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA