Junglewise Threat Intelligence

CVE-2022-50943: Moodle LMS cross-site scripting in course search

CVE-2022-50943 · Severity: medium · CVSS 6.1 · Published 2026-05-10

Technologies: Moodle. Vendors: Moodle.

Executive brief

Moodle LMS, a widely used open-source learning platform, is vulnerable to a security flaw in its course search feature. An attacker can use this to run malicious scripts in the browsers of other users, potentially leading to the theft of login sessions or sensitive personal information. This could allow an unauthorized person to take over user accounts or disrupt educational activities.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Moodle LMS versions up to and including 4.0.0. The flaw is located in 'course/search.php' due to improper neutralization of the 'search' parameter before it is echoed back to the page via the search_courses method. An unauthenticated remote attacker can craft a malicious URL containing a JavaScript payload; if a user visits this link, the script executes in their browser context. This can be used to steal session cookies, perform actions on behalf of the user, or deface the site. Public exploit code is available.

Affected products

  • Moodle Moodle LMS 4.0.0 and earlier

Timeline

  • 2022-10-26: other: Vulnerability discovered by researcher
  • 2023-03-28: disclosed: Exploit published on Exploit-DB
  • 2026-05-10: advisory: NVD/VulnCheck advisory published

References

Related threats