CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

27 May 2026, 19:56

Type Values Removed Values Added
References () https://git.in.moodle.com/moodle - () https://git.in.moodle.com/moodle - Product
References () https://moodle.org/ - () https://moodle.org/ - Product
References () https://www.exploit-db.com/exploits/51115 - () https://www.exploit-db.com/exploits/51115 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/moodle-lms-cross-site-scripting-via-course-search-php - () https://www.vulncheck.com/advisories/moodle-lms-cross-site-scripting-via-course-search-php - Third Party Advisory
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
First Time Moodle moodle
Moodle

10 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 13:16

Updated : 2026-05-27 19:56


NVD link : CVE-2022-50943

Mitre link : CVE-2022-50943

CVE.ORG link : CVE-2022-50943


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')