Multiple vulnerabilities in Moodle



Published: 2022-09-19
Risk Medium
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2022-40316
CVE-2022-40315
CVE-2022-40314
CVE-2022-40313
CWE-ID CWE-264
CWE-89
CWE-502
CWE-79
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Moodle
Web applications / Other software

Vendor moodle.org

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU67471

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-40316

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to the H5P activity attempts report does not respect group permissions when displaying information to non-editing teachers about attempts/users in groups they should not have access to. A remote user can gain access to sensitive information.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Moodle: 4.0.0 - 4.0.3, 3.11 - 3.11.9, 3.10.0 - 3.10.11, 3.9.0 - 3.9.16


CPE2.3 External links

http://moodle.org/mod/forum/discuss.php?d=438395
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71662
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72012

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) SQL injection

EUVDB-ID: #VU67470

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-40315

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Exploit availability: No

Description

The vulnerability allows a remote user to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in the "browse list of users" site administration page. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.


Mitigation

Install updates from vendor's website.

Vulnerable software versions

Moodle: 4.0.0 - 4.0.3, 3.11 - 3.11.9, 3.10.0 - 3.10.11, 3.9.0 - 3.9.16


CPE2.3 External links

http://moodle.org/mod/forum/discuss.php?d=438394
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75283

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Deserialization of Untrusted Data

EUVDB-ID: #VU67469

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-40314

CWE-ID: CWE-502 - Deserialization of Untrusted Data

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when restoring backup files originating from Moodle. A remote attacker can trick the victim into restoring the website from a malformed backup and execute arbitrary code on the target system.


Mitigation

Install updates from vendor's website.

Vulnerable software versions

Moodle: 4.0.0 - 4.0.3, 3.11 - 3.11.9, 3.10.0 - 3.10.11, 3.9.0 - 3.9.16


CPE2.3 External links

http://moodle.org/mod/forum/discuss.php?d=438393
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Cross-site scripting

EUVDB-ID: #VU67468

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-40313

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data within Mustache template helpers. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Moodle: 4.0.0 - 4.0.3, 3.11 - 3.11.9, 3.10.0 - 3.10.11, 3.9.0 - 3.9.16


CPE2.3 External links

http://moodle.org/mod/forum/discuss.php?d=438392
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-68066

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###