Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32473 | Med | 0.35 | 5.3 | 0.01 | Mar 11, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected | ||
| CVE-2021-43560 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events. | ||
| CVE-2021-32244 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2021 | Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field. | ||
| CVE-2021-20185 | Med | 0.35 | 5.3 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages. | ||
| CVE-2021-20186 | Med | 0.35 | 5.4 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS. | ||
| CVE-2020-25703 | Med | 0.35 | 5.3 | 0.02 | Nov 19, 2020 | The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10. | ||
| CVE-2020-25700 | Med | 0.35 | 6.5 | 0.01 | Nov 19, 2020 | In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10. | ||
| CVE-2019-14883 | Med | 0.35 | 5.3 | 0.01 | Mar 18, 2020 | A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their… | ||
| CVE-2019-18210 | Med | 0.35 | 5.4 | 0.01 | Feb 11, 2020 | Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor… | ||
| CVE-2012-1169 | Med | 0.35 | 5.3 | 0.02 | Nov 14, 2019 | Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. | ||
| CVE-2018-1135 | Med | 0.35 | 6.5 | 0.01 | May 25, 2018 | An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL. | ||
| CVE-2018-1134 | Med | 0.35 | 6.5 | 0.01 | May 25, 2018 | An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL. | ||
| CVE-2018-1045 | Med | 0.35 | 5.4 | 0.01 | Jan 22, 2018 | In Moodle 3.x, there is XSS via a calendar event name. | ||
| CVE-2017-7532 | Med | 0.35 | 6.5 | 0.01 | Jul 17, 2017 | In Moodle 3.x, course creators are able to change system default settings for courses. | ||
| CVE-2017-7490 | Med | 0.35 | 5.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing. | ||
| CVE-2016-3731 | Med | 0.35 | 5.3 | 0.02 | Apr 20, 2017 | Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions. | ||
| CVE-2017-7298 | Med | 0.35 | 5.4 | 0.01 | Mar 29, 2017 | In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. | ||
| CVE-2017-2643 | Med | 0.35 | 5.3 | 0.02 | Mar 26, 2017 | In Moodle 3.2.x, global search displays user names for unauthenticated users. | ||
| CVE-2017-2576 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums. | ||
| CVE-2016-8644 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. |
- risk 0.35cvss 5.3epss 0.01
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected
- risk 0.35cvss 5.3epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.
- risk 0.35cvss 5.3epss 0.01
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.
- risk 0.35cvss 5.4epss 0.01
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
- risk 0.35cvss 5.3epss 0.02
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.
- risk 0.35cvss 6.5epss 0.01
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their…
- risk 0.35cvss 5.4epss 0.01
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor…
- risk 0.35cvss 5.3epss 0.02
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.
- risk 0.35cvss 5.4epss 0.01
In Moodle 3.x, there is XSS via a calendar event name.
- risk 0.35cvss 6.5epss 0.01
In Moodle 3.x, course creators are able to change system default settings for courses.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
- risk 0.35cvss 5.3epss 0.02
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
- risk 0.35cvss 5.4epss 0.01
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
- risk 0.35cvss 5.3epss 0.02
In Moodle 3.2.x, global search displays user names for unauthenticated users.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
Page 7 of 32