Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-34008 Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. Moodle 4.1.10 / 4.2.7+ Fix from $1,9502024-05-31 HIGH 7.5 CVE-2024-34009 Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA… Moodle 4.3.4+ Fix from $1,9502024-05-31 MEDIUM 6.5 CVE-2024-34002 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedba… Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 6.5 CVE-2024-34004 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki m… Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 6.5 CVE-2024-34005 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa… Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 5.9 CVE-2024-34003 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore worksh… Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 HIGH 8.4 CVE-2024-34001 Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. Moodle 4.1.10 / 4.2.7+ Fix from $1,9502024-05-31 CRITICAL 9.8 CVE-2024-33999 The referrer URL used by MFA required additional sanitizing, rather than being used directly. Moodle 4.3.4+ Fix from $2,3002024-05-31 MEDIUM 6.2 CVE-2024-33996 Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did … Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 6.1 CVE-2024-33997 Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation. Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 5.4 CVE-2024-33998 Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 5.4 CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per… Moodle Mitigation only Fix from $1,6002024-03-22 MEDIUM 6.1 CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. Moodle No fix yet Fix from $1,6002024-03-21 HIGH 8.8 CVE-2024-25982 The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. Moodle 4.1.9 / 4.2.6+ Fix from $1,9502024-02-19 MEDIUM 5.3 CVE-2024-25980 Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only prov… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 MEDIUM 5.3 CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 MEDIUM 5.3 CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise ava… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 HIGH 7.5 CVE-2024-25978 Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. Moodle 4.1.9 / 4.2.6+ Fix from $1,9502024-02-19 MEDIUM 5.3 CVE-2024-25979 The URL parameters accepted by forum search were not limited to the allowed parameters. Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 CRITICAL 9.8 CVE-2023-5550 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the … Moodle 3.9.24 / 3.11.17+ Fix from $2,3002023-11-09 MEDIUM 6.1 CVE-2023-5547 The course upload preview contained an XSS risk for users uploading unsafe data. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 5.4 CVE-2023-5546 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 4.0.11 / 4.1.6+ Fix from $1,6002023-11-09 MEDIUM 5.3 CVE-2023-5548 Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 5.3 CVE-2023-5549 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav… Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 HIGH 8.8 CVE-2023-5540 A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. Moodle 3.9.24 / 3.11.17+ Fix from $1,9502023-11-09 MEDIUM 6.1 CVE-2023-5541 The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 5.4 CVE-2023-5544 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 5.3 CVE-2023-5545 H5P metadata automatically populated the author with the user's username, which could be sensitive information. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 HIGH 8.8 CVE-2023-5539 A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. Moodle 3.9.24 / 3.11.17+ Fix from $1,9502023-11-09 MEDIUM 5.4 CVE-2023-46858 Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "S… Moodle No fix yet Fix from $1,6002023-10-29