CVE-2022-30596
PHP vulnerability analysis and mitigation

Overview

A stored XSS vulnerability (CVE-2022-30596) was discovered in Moodle that affected the bulk marker allocation form for assignments. The vulnerability was discovered in May 2022 and affected Moodle versions 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13, and earlier unsupported versions. The issue was reported by Paul Holden and required additional sanitizing of ID numbers displayed when bulk allocating markers to assignments (Moodle Forum).

Technical details

The vulnerability was identified as a stored Cross-Site Scripting (XSS) risk in the assignment bulk marker allocation form, specifically related to the display of user ID numbers. The issue required additional sanitization of input fields to prevent potential XSS attacks. The severity was rated as Minor according to Moodle's security assessment (Moodle Forum).

Impact

The vulnerability could allow an attacker to execute malicious scripts through stored XSS in the assignment bulk marker allocation form, potentially compromising user data or performing unauthorized actions in the context of other users' sessions (NVD).

Mitigation and workarounds

The vulnerability was fixed in Moodle versions 4.0.1, 3.11.7, 3.10.11, and 3.9.14. Users are advised to upgrade to these or later versions to mitigate the risk. The fix involved implementing additional sanitization for ID numbers displayed in the bulk marker allocation form (Moodle Forum).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21857HIGH8.3
  • PHPPHP
  • redaxo/source
NoYesJan 07, 2026
CVE-2025-61676MEDIUM6.1
  • PHPPHP
  • october/system
NoYesJan 10, 2026
CVE-2025-61674MEDIUM6.1
  • PHPPHP
  • october/system
NoYesJan 10, 2026
CVE-2026-21896MEDIUM5.8
  • PHPPHP
  • getkirby/cms
NoYesJan 08, 2026
CVE-2026-22242MEDIUM4.9
  • PHPPHP
  • coreshop/core-shop
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management