Filtered by vendor Moodle
Subscribe
Total
526 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-4281 | 1 Moodle | 1 Moodle | 2023-11-07 | 6.8 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course. | |||||
CVE-2011-4280 | 2 Moodle, Nimish Pachapurkar | 2 Moodle, Spike Phpcoverage | 2023-11-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-4279 | 1 Moodle | 1 Moodle | 2023-11-07 | 5.0 MEDIUM | N/A |
Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista. | |||||
CVE-2011-4278 | 1 Moodle | 1 Moodle | 2023-11-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-4133 | 1 Moodle | 1 Moodle | 2023-11-07 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block. | |||||
CVE-2004-2232 | 1 Moodle | 1 Moodle | 2023-11-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements. | |||||
CVE-2022-40316 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2023-08-08 | N/A | 4.3 MEDIUM |
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | |||||
CVE-2022-0985 | 1 Moodle | 1 Moodle | 2023-07-21 | 4.0 MEDIUM | 4.3 MEDIUM |
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. | |||||
CVE-2022-40208 | 1 Moodle | 1 Moodle | 2023-03-30 | N/A | 4.3 MEDIUM |
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | |||||
CVE-2021-36403 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.3 MEDIUM |
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk. | |||||
CVE-2021-36402 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.3 MEDIUM |
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. | |||||
CVE-2021-36401 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 4.8 MEDIUM |
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. | |||||
CVE-2021-36400 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.3 MEDIUM |
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. | |||||
CVE-2021-36399 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.4 MEDIUM |
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk. | |||||
CVE-2021-36398 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.4 MEDIUM |
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. | |||||
CVE-2021-36397 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 5.3 MEDIUM |
In Moodle, insufficient capability checks meant message deletions were not limited to the current user. | |||||
CVE-2021-36396 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 7.5 HIGH |
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. | |||||
CVE-2021-36395 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 7.5 HIGH |
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | |||||
CVE-2021-36394 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 9.8 CRITICAL |
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | |||||
CVE-2021-36393 | 1 Moodle | 1 Moodle | 2023-03-13 | N/A | 9.8 CRITICAL |
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. |