CVE-2022-46147

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-46147
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-46147.json
Aliases
Published
2022-11-28T21:15:10Z
Modified
2023-11-29T09:53:16.555352Z
Details

Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.

References

Affected packages

Git / github.com/openedx/xblock-drag-and-drop-v2

Affected ranges

Type
GIT
Repo
https://github.com/openedx/xblock-drag-and-drop-v2
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

2.*

2.1.5
2.2.6
2.2.8
2.3.1

v2.*

v2.0.1
v2.0.10
v2.0.11
v2.0.12
v2.0.14
v2.0.15
v2.0.16
v2.0.17
v2.0.18
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.6
v2.1.7
v2.1.8
v2.2.0
v2.2.1
v2.2.10
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.8
v2.2.9
v2.3.0
v2.3.10
v2.3.11
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.2
v2.5.0
v2.6.0
v2.7.0