VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2024-48899MedNov 20, 2024
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

  • CVE-2024-34006MedMay 31, 2024
    risk 0.21cvss 4.3epss 0.00

    The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

  • CVE-2024-34000MedMay 31, 2024
    risk 0.21cvss 4.3epss 0.00

    ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

  • CVE-2024-25982MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

  • CVE-2024-25981MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-25980MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

  • CVE-2023-5546MedNov 9, 2023
    risk 0.21cvss 4.3epss 0.01

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

  • CVE-2022-40208MedMar 24, 2023
    risk 0.21cvss 4.3epss 0.01

    In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

  • CVE-2023-28336MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

  • CVE-2023-28334MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Authenticated users were able to enumerate other users' names via the learning plans page.

  • CVE-2023-1402MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.

  • CVE-2022-30598MedMay 18, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

  • CVE-2022-0984MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

  • CVE-2022-0985MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

  • CVE-2022-0334MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…

  • CVE-2021-20283MedMar 15, 2021
    risk 0.21cvss 4.3epss 0.01

    The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2012-1159MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2: Overview report allows users to see hidden courses

  • CVE-2012-1157MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

  • CVE-2019-10189MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.

  • CVE-2019-10188MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

Page 13 of 32