VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2024-48897MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

  • CVE-2024-48896MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.

  • CVE-2024-43439MedNov 11, 2024
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

  • CVE-2024-38277MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

  • CVE-2024-38273MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

  • CVE-2024-33998MedMay 31, 2024
    risk 0.28cvss 5.4epss 0.00

    Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

  • CVE-2022-40316MedSep 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2021-40695MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

  • CVE-2021-40692MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient capability checks made it possible for teachers to download users outside of their courses.

  • CVE-2021-40691MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    A session hijack risk was identified in the Shibboleth authentication plugin.

  • CVE-2020-1754MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • CVE-2020-1691MedAug 5, 2022
    risk 0.28cvss 5.4epss 0.01

    In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

  • CVE-2022-30597MedMay 18, 2022
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • CVE-2022-30596MedMay 18, 2022
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-32477MedMar 11, 2022
    risk 0.28cvss 4.3epss 0.01

    The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.

  • CVE-2021-32472MedMar 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.

  • CVE-2019-14829MedMar 19, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

  • CVE-2019-14828MedMar 19, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be…

  • CVE-2021-20282MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20281MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

Page 10 of 32