VulnerabilityModified
CVE-2022-46147
Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields.
MEDIUM 6.1EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- openedx/xblock-drag-and-drop-v2
- Source
- security-advisories@github.com
References
- https://github.com/openedx/xblock-drag-and-drop-v2/commit/68887d1b4a44325d2de7573d450e41129ba98b1aPatch, Release Notes, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/pull/295#issuecomment-1277693864Exploit, Patch, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/releases/tag/v3.0.0Patch, Release Notes, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/security/advisories/GHSA-qv6c-367r-3w6qPatch, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/commit/68887d1b4a44325d2de7573d450e41129ba98b1aPatch, Release Notes, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/pull/295#issuecomment-1277693864Exploit, Patch, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/releases/tag/v3.0.0Patch, Release Notes, Third Party Advisory
- https://github.com/openedx/xblock-drag-and-drop-v2/security/advisories/GHSA-qv6c-367r-3w6qPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.