Medium severity6.1NVD Advisory· Published May 10, 2026· Updated May 27, 2026
CVE-2022-50943
CVE-2022-50943
Description
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51115nvdExploitVDB Entry
- www.vulncheck.com/advisories/moodle-lms-cross-site-scripting-via-course-search-phpnvdThird Party Advisory
- moodle.orgnvdProduct
News mentions
0No linked articles in our index yet.