S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-35653 Scanner

CVE-2022-35653 scanner - Cross-Site Scripting vulnerability in Moodle

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
10
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-35653
6.1
CVSS

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Moodleby n/a
Fixed in moodle 4.0.2, moodle 3.11.8, moodle 3.9.15
Updated Aug 22, 2026View on NVD →
Detail

Moodle is a widely adopted open-source learning management system (LMS) used by educational institutions and organizations globally to create online learning portals. It supports a wide range of activities and resources, providing educators and students with a flexible and user-friendly e-learning platform. Moodle's LTI (Learning Tools Interoperability) module facilitates integration with external learning tools and content, enhancing the learning experience. As an essential tool in the digital learning environment, Moodle's security is critical for safeguarding educational content and user data.

The reflected Cross-Site Scripting (XSS) vulnerability in Moodle's LTI module, identified as CVE-2022-35653, arises from insufficient input sanitization. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted URL, potentially leading to unauthorized access to sensitive information, session hijacking, and other malicious actions performed on behalf of the user.

CVE-2022-35653 specifically targets the LTI module's auth.php file, where user-supplied input is not adequately sanitized before being included in the webpage. This flaw enables attackers to embed malicious scripts in the URL parameters, which are executed in the victim's browser upon accessing the compromised link. The vulnerability poses a significant risk to users by exploiting the trust relationship between the user and the Moodle platform.

Exploitation of this XSS vulnerability could lead to various adverse effects, including stealing of cookies, session tokens, or other sensitive information, impersonation of user actions, redirection to malicious websites, and potentially leveraging the vulnerability to launch further attacks. It undermines the security and integrity of the Moodle platform and can significantly impact the privacy and safety of its users.

S4E (S4E) provides a comprehensive security scanning solution that can identify vulnerabilities like CVE-2022-35653 in Moodle. By utilizing S4E's services, educational institutions and organizations can proactively detect and remediate security weaknesses, ensuring the protection of their digital learning environments. Membership with S4E offers ongoing security assessments, expert remediation guidance, and enhanced cyber resilience, safeguarding against potential cyber threats.

 

References

Solution Advice
  1. Update Moodle to the latest version where this vulnerability has been fixed.
  2. Apply patches or updates provided by Moodle for the LTI module if available.
  3. Ensure proper input validation and sanitization mechanisms are implemented to prevent XSS attacks.
  4. Conduct regular security audits and vulnerability assessments to identify and mitigate potential security issues.
  5. Educate users about the risks associated with XSS vulnerabilities and encourage safe browsing practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.