The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they…
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a…
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from maliciou…
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ…
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them in…
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden us…
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil…
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users…
A flaw was found in moodle. A local file may include risks when restoring block backups.
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi…
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is avail…
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a ne…
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintent…
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.