Related Vulnerabilities: CVE-2022-30596  

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

Description

The MITRE CVE dictionary describes this issue as:

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

Additional Information

  • Bugzilla 2083583: CVE-2022-30596 moodle: Stored XSS in assignment bulk marker allocation form via user ID number
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2022-30596