MEDIUM
Moodle: reflected xss risk in blog search
Published Feb 17, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.85%
Description
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-76861 Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=2162547 Issue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-grmj-gpwm-98ww Advisory
- https://moodle.org/mod/forum/discuss.php?d=443273#p1782022 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-23922
| Link | Providers | Tags |
|---|---|---|
| http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-76861 | Patch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2162547 | Issue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-grmj-gpwm-98ww | Advisory | |
| https://moodle.org/mod/forum/discuss.php?d=443273#p1782022 | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-23922 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Feb 17, 2023
Updated Aug 2, 2024
Reserved Jan 19, 2023
Link CVE-2023-23922
CISA Vulnrichment
GHSA-GRMJ-GPWM-98WW Updated Jul 18, 2024