CVE-2022-50943: Moodle LMS 4.0 Cross-Site Scripting via course search.php
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50943?
CVE-2022-50943 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2022-50943?
To fix CVE-2022-50943, update your Moodle LMS to version 4.0.1 or later where the vulnerability is patched.
Who is affected by CVE-2022-50943?
CVE-2022-50943 affects users of Moodle LMS version 4.0.
What type of vulnerability is CVE-2022-50943?
CVE-2022-50943 is a cross-site scripting (XSS) vulnerability enabling attackers to inject malicious scripts.
Can CVE-2022-50943 be exploited without authentication?
Yes, CVE-2022-50943 can be exploited by unauthenticated attackers through the search parameter.