Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20280 | Med | 0.28 | 5.4 | 0.01 | Mar 15, 2021 | Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20279 | Med | 0.28 | 5.4 | 0.01 | Mar 15, 2021 | The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20184 | Med | 0.28 | 4.3 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades. | ||
| CVE-2021-20183 | Med | 0.28 | 5.4 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries. | ||
| CVE-2020-25701 | Med | 0.28 | 5.3 | 0.01 | Nov 19, 2020 | If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to… | ||
| CVE-2019-14879 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2020 | A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable). | ||
| CVE-2012-1161 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results | ||
| CVE-2012-1158 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export | ||
| CVE-2019-3848 | Med | 0.28 | 4.3 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was… | ||
| CVE-2019-3808 | Med | 0.28 | 5.4 | 0.01 | Mar 25, 2019 | A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is… | ||
| CVE-2017-15110 | Med | 0.28 | 4.3 | 0.01 | Nov 20, 2017 | In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other… | ||
| CVE-2017-7491 | Med | 0.28 | 4.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting. | ||
| CVE-2016-3732 | Med | 0.28 | 4.3 | 0.01 | Apr 20, 2017 | The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. | ||
| CVE-2016-8643 | Med | 0.28 | 4.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | ||
| CVE-2016-8642 | Med | 0.28 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. | ||
| CVE-2016-5014 | Med | 0.28 | 5.4 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | ||
| CVE-2016-5013 | Med | 0.28 | 5.4 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. | ||
| CVE-2016-2190 | Med | 0.28 | 5.3 | 0.02 | May 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log. | ||
| CVE-2015-5336 | Med | 0.28 | 5.4 | 0.01 | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering… | ||
| CVE-2015-5272 | Med | 0.28 | 4.3 | 0.02 | Feb 22, 2016 | The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants." |
- risk 0.28cvss 5.4epss 0.01
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 5.4epss 0.01
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 4.3epss 0.01
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
- risk 0.28cvss 5.4epss 0.01
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.
- risk 0.28cvss 5.3epss 0.01
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to…
- risk 0.28cvss 5.4epss 0.01
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
- risk 0.28cvss 4.3epss 0.01
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
- risk 0.28cvss 4.3epss 0.01
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…
- risk 0.28cvss 5.4epss 0.01
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is…
- risk 0.28cvss 4.3epss 0.01
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other…
- risk 0.28cvss 4.3epss 0.01
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
- risk 0.28cvss 4.3epss 0.01
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.
- risk 0.28cvss 4.3epss 0.01
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
- risk 0.28cvss 5.3epss 0.01
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
- risk 0.28cvss 5.4epss 0.01
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
- risk 0.28cvss 5.4epss 0.01
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
- risk 0.28cvss 5.3epss 0.02
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
- risk 0.28cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering…
- risk 0.28cvss 4.3epss 0.02
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
Page 11 of 32