Loading HuntDB...

GHSA-xv72-6pgh-cjj8

GitHub Security Advisory

Moodle stored-XSS vulnerability in some "social" user profile fields

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Affected Packages

Packagist moodle/moodle
Affected versions: 3.11 (fixed in 3.11.11)
Packagist moodle/moodle
Affected versions: 4.0 (fixed in 4.0.5)

Related CVEs

Key Information

GHSA ID
GHSA-xv72-6pgh-cjj8
Published
November 23, 2022 3:30 PM
Last Modified
April 23, 2024 11:43 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.