Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48899 | Med | 0.21 | 4.3 | 0.00 | Nov 20, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to. | ||
| CVE-2024-34006 | Med | 0.21 | 4.3 | 0.00 | May 31, 2024 | The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered. | ||
| CVE-2024-34000 | Med | 0.21 | 4.3 | 0.00 | May 31, 2024 | ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2024-25982 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2024-25981 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | ||
| CVE-2024-25980 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | ||
| CVE-2023-5546 | Med | 0.21 | 4.3 | 0.01 | Nov 9, 2023 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2022-40208 | Med | 0.21 | 4.3 | 0.01 | Mar 24, 2023 | In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | ||
| CVE-2023-28336 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. | ||
| CVE-2023-28334 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | Authenticated users were able to enumerate other users' names via the learning plans page. | ||
| CVE-2023-1402 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. | ||
| CVE-2022-30598 | Med | 0.21 | 4.3 | 0.01 | May 18, 2022 | A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it. | ||
| CVE-2022-0984 | Med | 0.21 | 4.3 | 0.01 | Apr 29, 2022 | Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges. | ||
| CVE-2022-0985 | Med | 0.21 | 4.3 | 0.01 | Apr 29, 2022 | Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. | ||
| CVE-2022-0334 | Med | 0.21 | 4.3 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view… | ||
| CVE-2021-20283 | Med | 0.21 | 4.3 | 0.01 | Mar 15, 2021 | The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2012-1159 | Med | 0.21 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2: Overview report allows users to see hidden courses | ||
| CVE-2012-1157 | Med | 0.21 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default | ||
| CVE-2019-10189 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment. | ||
| CVE-2019-10188 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz. |
- risk 0.21cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
- risk 0.21cvss 4.3epss 0.00
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
- risk 0.21cvss 4.3epss 0.00
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
- risk 0.21cvss 4.3epss 0.01
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
- risk 0.21cvss 4.3epss 0.01
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
- risk 0.21cvss 4.3epss 0.01
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
- risk 0.21cvss 4.3epss 0.01
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
- risk 0.21cvss 4.3epss 0.01
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
- risk 0.21cvss 4.3epss 0.01
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
- risk 0.21cvss 4.3epss 0.01
Authenticated users were able to enumerate other users' names via the learning plans page.
- risk 0.21cvss 4.3epss 0.01
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
- risk 0.21cvss 4.3epss 0.01
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
- risk 0.21cvss 4.3epss 0.01
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…
- risk 0.21cvss 4.3epss 0.01
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.21cvss 4.3epss 0.01
Moodle before 2.2.2: Overview report allows users to see hidden courses
- risk 0.21cvss 4.3epss 0.01
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
Page 13 of 32