CVE-2022-30596
Description
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
CWE
- CWE-79 — CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected
- n/a / moodle — v=Affects : 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions [affected]
CVSS
- (none)
References
- https://moodle.org/mod/forum/discuss.php?d=434578 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=2083583 x_refsource_MISC
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74204 x_refsource_MISC
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PIMSIRKCFLIC646K4GMUSZU7THOUVPAJ/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OGF35EN5K2R6X3NTY3XPZSJ3UDASMXI6/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCTWSE3JDMSYL7DPCMXMMJEXZSS6VIA5/ vendor-advisory, x_refsource_FEDORA
Source
cvelistV5-main/cves/2022/30xxx/CVE-2022-30596.json