Moodle
by Moodle
Source repositories
CVEs (570)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-1168 | 0.00 | — | 0.02 | Nov 14, 2019 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. | |||
| CVE-2012-1155 | 0.00 | — | 0.02 | Nov 14, 2019 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | |||
| CVE-2019-10186 | 0.00 | — | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool. | |||
| CVE-2019-10187 | 0.00 | — | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to. | |||
| CVE-2019-10188 | 0.00 | — | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz. | |||
| CVE-2019-10189 | 0.00 | — | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment. | |||
| CVE-2019-10154 | 0.00 | — | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. | |||
| CVE-2019-10134 | 0.00 | — | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded. | |||
| CVE-2019-10133 | 0.00 | — | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. | |||
| CVE-2019-3847 | 0.00 | — | 0.02 | Mar 27, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was… | |||
| CVE-2019-3852 | 0.00 | — | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities | |||
| CVE-2019-3851 | 0.00 | — | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. | |||
| CVE-2019-3850 | 0.00 | — | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header… | |||
| CVE-2019-3849 | 0.00 | — | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | |||
| CVE-2019-3848 | 0.00 | — | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was… | |||
| CVE-2019-3809 | 0.00 | — | 0.01 | Mar 25, 2019 | A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests… | |||
| CVE-2019-3808 | 0.00 | — | 0.01 | Mar 25, 2019 | A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is… | |||
| CVE-2019-6970 | 0.00 | — | 0.01 | Mar 18, 2019 | Moodle 3.5.x before 3.5.4 allows SSRF. | |||
| CVE-2015-3181 | 0.00 | — | 0.02 | Jun 1, 2015 | files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended… | |||
| CVE-2015-3180 | 0.00 | — | 0.02 | Jun 1, 2015 | lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment. |
- CVE-2012-1168Nov 14, 2019risk 0.00cvss —epss 0.02
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
- CVE-2012-1155Nov 14, 2019risk 0.00cvss —epss 0.02
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
- CVE-2019-10186Jul 31, 2019risk 0.00cvss —epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
- CVE-2019-10187Jul 31, 2019risk 0.00cvss —epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
- CVE-2019-10188Jul 31, 2019risk 0.00cvss —epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
- CVE-2019-10189Jul 31, 2019risk 0.00cvss —epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
- CVE-2019-10154Jun 26, 2019risk 0.00cvss —epss 0.01
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
- CVE-2019-10134Jun 26, 2019risk 0.00cvss —epss 0.01
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
- CVE-2019-10133Jun 26, 2019risk 0.00cvss —epss 0.01
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
- CVE-2019-3847Mar 27, 2019risk 0.00cvss —epss 0.02
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was…
- CVE-2019-3852Mar 26, 2019risk 0.00cvss —epss 0.01
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
- CVE-2019-3851Mar 26, 2019risk 0.00cvss —epss 0.01
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
- CVE-2019-3850Mar 26, 2019risk 0.00cvss —epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header…
- CVE-2019-3849Mar 26, 2019risk 0.00cvss —epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
- CVE-2019-3848Mar 26, 2019risk 0.00cvss —epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…
- CVE-2019-3809Mar 25, 2019risk 0.00cvss —epss 0.01
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests…
- CVE-2019-3808Mar 25, 2019risk 0.00cvss —epss 0.01
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is…
- CVE-2019-6970Mar 18, 2019risk 0.00cvss —epss 0.01
Moodle 3.5.x before 3.5.4 allows SSRF.
- CVE-2015-3181Jun 1, 2015risk 0.00cvss —epss 0.02
files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended…
- CVE-2015-3180Jun 1, 2015risk 0.00cvss —epss 0.02
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
Page 15 of 29