VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2023-5543LowNov 9, 2023
    risk 0.00cvss 3.3epss 0.00

    When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

  • CVE-2023-35133HigJun 22, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

  • CVE-2023-35132MedJun 22, 2023
    risk 0.00cvss 6.3epss 0.01

    A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

  • CVE-2023-35131MedJun 22, 2023
    risk 0.00cvss 6.1epss 0.01

    Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

  • CVE-2023-23923HigFeb 17, 2023
    risk 0.00cvss 8.2epss 0.01

    The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted…

  • CVE-2023-23922MedFeb 17, 2023
    risk 0.00cvss 6.1epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2023-23921MedFeb 17, 2023
    risk 0.00cvss 6.1epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context…

  • CVE-2022-45152CriNov 25, 2022
    risk 0.00cvss 9.1epss 0.01

    A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An…

  • CVE-2022-45151MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.01

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2022-45150MedNov 23, 2022
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in…

  • CVE-2022-45149MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the…

  • CVE-2022-2986HigOct 6, 2022
    risk 0.00cvss 8.8epss 0.00

    Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-35653MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.05

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…

  • CVE-2022-35651MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2019-14827MedMay 17, 2021
    risk 0.00cvss 6.1epss 0.01

    A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another…

  • CVE-2019-3809MedMar 25, 2019
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests…

  • CVE-2018-16854MedNov 26, 2018
    risk 0.00cvss 6.5epss 0.02

    A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

  • CVE-2018-1082HigApr 4, 2018
    risk 0.00cvss 8.1epss 0.02

    A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

  • CVE-2018-1081MedApr 4, 2018
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…

Page 18 of 32