{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "35"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "36"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "8.0"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "3.9.0"
              },
              {
                "fixed": "3.9.15"
              },
              {
                "introduced": "3.11.0"
              },
              {
                "fixed": "3.11.8"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-NA"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-beta"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-rc1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-rc2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-rc3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.0-rc4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.0.1"
              }
            ]
          },
          "events": [
            {
              "introduced": "500c131eb49771e36f68d151dfa37fef5a9bc2df"
            },
            {
              "fixed": "84d3ae1b081ba764a54baf40ed063b96764c81c4"
            },
            {
              "introduced": "94f2d3fc4b974c5c7d500988c56b7ca15f58d7ec"
            },
            {
              "fixed": "b8fd606243238b9624b12c0fba6c39f74b0c0869"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "8b359ad7a63cf219110bca80552fe3d4ea2a635d"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "1d99ba19a21d57e9f1ed4211a8eeee00e50b7baf"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "f62cd4484e98b928b8f26d98022f25e48fd36464"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "5423e5f4435098bed40763eccbb5931a3da063a3"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4ca5665aa0ef1adf53b0272889bc0bacbd8f6e47"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "f801189795d30814953f2543f225785b3ee0606e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "ac9e395ed6661fa76ba7e1d6a77e47631e88a9ca"
            }
          ],
          "repo": "https://github.com/moodle/moodle",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.",
  "id": "CVE-2022-35653",
  "modified": "2026-03-15T21:47:22.562103524Z",
  "published": "2022-07-25T16:15:08.520Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106277"
    },
    {
      "type": "FIX",
      "url": "https://moodle.org/mod/forum/discuss.php?d=436460"
    },
    {
      "type": "FIX",
      "url": "http://git.moodle.org/gw?p=moodle.git\u0026a=search\u0026h=HEAD\u0026st=commit\u0026s=MDL-72299"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}