VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2021-32473MedMar 11, 2022
    risk 0.35cvss 5.3epss 0.01

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected

  • CVE-2021-43560MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

  • CVE-2021-32244MedJun 16, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

  • CVE-2021-20185MedJan 28, 2021
    risk 0.35cvss 5.3epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

  • CVE-2021-20186MedJan 28, 2021
    risk 0.35cvss 5.4epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

  • CVE-2020-25703MedNov 19, 2020
    risk 0.35cvss 5.3epss 0.02

    The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

  • CVE-2020-25700MedNov 19, 2020
    risk 0.35cvss 6.5epss 0.01

    In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

  • CVE-2019-14883MedMar 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their…

  • CVE-2019-18210MedFeb 11, 2020
    risk 0.35cvss 5.4epss 0.01

    Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor…

  • CVE-2012-1169MedNov 14, 2019
    risk 0.35cvss 5.3epss 0.02

    Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.

  • CVE-2018-1135MedMay 25, 2018
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.

  • CVE-2018-1134MedMay 25, 2018
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.

  • CVE-2018-1045MedJan 22, 2018
    risk 0.35cvss 5.4epss 0.01

    In Moodle 3.x, there is XSS via a calendar event name.

  • CVE-2017-7532MedJul 17, 2017
    risk 0.35cvss 6.5epss 0.01

    In Moodle 3.x, course creators are able to change system default settings for courses.

  • CVE-2017-7490MedMay 15, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

  • CVE-2016-3731MedApr 20, 2017
    risk 0.35cvss 5.3epss 0.02

    Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

  • CVE-2017-7298MedMar 29, 2017
    risk 0.35cvss 5.4epss 0.01

    In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.

  • CVE-2017-2643MedMar 26, 2017
    risk 0.35cvss 5.3epss 0.02

    In Moodle 3.2.x, global search displays user names for unauthenticated users.

  • CVE-2017-2576MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

  • CVE-2016-8644MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

Page 7 of 32