cbcvebase.
CVE-2022-30596
published 2022-05-18

CVE-2022-30596: A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

Affected

13 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
moodlemoodle
moodlemoodle
moodlemoodle>= 3.10 < 3.10.113.10.11
moodlemoodle>= 3.10 < 3.10.113.10.11
moodlemoodle>= 3.11 < 3.11.73.11.7
moodlemoodle>= 3.11 < 3.11.73.11.7
moodlemoodle>= 3.9 < 3.9.143.9.14
moodlemoodle>= 3.9 < 3.9.143.9.14
moodlemoodle>= 4.0 < 4.0.14.0.1
redhatenterprise_linux

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM