VYPR
Medium severity4.3NVD Advisory· Published May 25, 2018· Updated Jun 17, 2026

CVE-2018-1136

CVE-2018-1136

Description

An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 3.1, < 3.1.123.1.12
moodle/moodlePackagist
>= 3.2, < 3.2.93.2.9
moodle/moodlePackagist
>= 3.3, < 3.3.63.3.6
moodle/moodlePackagist
>= 3.4, < 3.4.33.4.3

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.