Moodle LMS 4.0 Cross-Site Scripting via course search.php
Vulnerability Description
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50943
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Saud Alenazi
References
More from Moodle
View All →Affected Vendor
Moodle
View all reports →