Back

HIGH

Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields

Published Nov 28, 2022

Description

Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 28, 2022
Updated Apr 22, 2025
Reserved Nov 28, 2022
CISA Vulnrichment
Updated Apr 22, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Nov 28, 2022
Updated Apr 22, 2025
Exploited since n/a
EUVD-2022-0416 GHSA-QV6C-367R-3W6Q