{"id":"CVE-2022-46147","aliases":["GHSA-qv6c-367r-3w6q","PYSEC-2022-43175"],"url":"https://o3.security/vulnerability/CVE-2022-46147","summary":"Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields","details":"Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.","published":"2022-11-28T00:00:00Z","modified":"2026-07-15T01:49:04.816637019Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"xblock-drag-and-drop-v2","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/openedx/xblock-drag-and-drop-v2/commit/68887d1b4a44325d2de7573d450e41129ba98b1a","label":"openedx/xblock-drag-and-drop-v2@68887d1"},"references":[{"type":"WEB","url":"https://github.com/openedx/xblock-drag-and-drop-v2/releases/tag/v3.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/46xxx/CVE-2022-46147.json"},{"type":"ADVISORY","url":"https://github.com/openedx/xblock-drag-and-drop-v2/security/advisories/GHSA-qv6c-367r-3w6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-46147"},{"type":"FIX","url":"https://github.com/openedx/xblock-drag-and-drop-v2/commit/68887d1b4a44325d2de7573d450e41129ba98b1a"},{"type":"FIX","url":"https://github.com/openedx/xblock-drag-and-drop-v2/pull/295#issuecomment-1277693864"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:04.816637019Z"}}