VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2024-34003MedMay 31, 2024
    risk 0.00cvss 5.9epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-34002MedMay 31, 2024
    risk 0.00cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-33999CriMay 31, 2024
    risk 0.00cvss 9.8epss 0.01

    The referrer URL used by MFA required additional sanitizing, rather than being used directly.

  • CVE-2024-33996MedMay 31, 2024
    risk 0.00cvss 6.2epss 0.00

    Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

  • CVE-2023-5543LowNov 9, 2023
    risk 0.00cvss 3.3epss 0.00

    When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

  • CVE-2023-35133HigJun 22, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

  • CVE-2023-35132MedJun 22, 2023
    risk 0.00cvss 6.3epss 0.01

    A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

  • CVE-2023-35131MedJun 22, 2023
    risk 0.00cvss 6.1epss 0.01

    Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

  • CVE-2023-23923HigFeb 17, 2023
    risk 0.00cvss 8.2epss 0.01

    The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted…

  • CVE-2023-23922MedFeb 17, 2023
    risk 0.00cvss 6.1epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2023-23921MedFeb 17, 2023
    risk 0.00cvss 6.1epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context…

  • CVE-2022-45152CriNov 25, 2022
    risk 0.00cvss 9.1epss 0.01

    A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An…

  • CVE-2022-45151MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.01

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2022-45150MedNov 23, 2022
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in…

  • CVE-2022-45149MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the…

  • CVE-2022-2986HigOct 6, 2022
    risk 0.00cvss 8.8epss 0.00

    Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-35653MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.05

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…

  • CVE-2022-35651MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2019-14827MedMay 17, 2021
    risk 0.00cvss 6.1epss 0.01

    A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another…

  • CVE-2019-15536CriAug 23, 2019
    risk 0.00cvss 9.8epss 0.01

    The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.

  • CVE-2019-3809MedMar 25, 2019
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests…

  • CVE-2018-16854MedNov 26, 2018
    risk 0.00cvss 6.5epss 0.02

    A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

  • CVE-2018-1082HigApr 4, 2018
    risk 0.00cvss 8.1epss 0.02

    A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

  • CVE-2018-1081MedApr 4, 2018
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…

  • CVE-2015-3181Jun 1, 2015
    risk 0.00cvss —epss 0.02

    files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended…

  • CVE-2015-3180Jun 1, 2015
    risk 0.00cvss —epss 0.02

    lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

  • CVE-2015-3179Jun 1, 2015
    risk 0.00cvss —epss 0.02

    login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

  • CVE-2015-3178Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external…

  • CVE-2015-3177Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

  • CVE-2015-3176Jun 1, 2015
    risk 0.00cvss —epss 0.02

    The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

  • CVE-2015-3175Jun 1, 2015
    risk 0.00cvss —epss 0.02

    Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL…

  • CVE-2015-3174Jun 1, 2015
    risk 0.00cvss —epss 0.01

    mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during…

  • CVE-2015-2273Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the…

  • CVE-2015-2272Jun 1, 2015
    risk 0.00cvss —epss 0.02

    login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass a forced-password-change requirement by creating a web-services token.

  • CVE-2015-2271Jun 1, 2015
    risk 0.00cvss —epss 0.02

    tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions…

  • CVE-2015-2270Jun 1, 2015
    risk 0.00cvss —epss 0.02

    lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain…

  • CVE-2015-2269Jun 1, 2015
    risk 0.00cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in…

  • CVE-2015-2268Jun 1, 2015
    risk 0.00cvss —epss 0.02

    filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular…

  • CVE-2015-2267Jun 1, 2015
    risk 0.00cvss —epss 0.02

    mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

  • CVE-2015-2266Jun 1, 2015
    risk 0.00cvss —epss 0.02

    message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive…

  • CVE-2015-1493Jun 1, 2015
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file…

  • CVE-2015-0218Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

  • CVE-2015-0217Jun 1, 2015
    risk 0.00cvss —epss 0.02

    filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper…

  • CVE-2015-0216Jun 1, 2015
    risk 0.00cvss —epss 0.01

    access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

  • CVE-2015-0215Jun 1, 2015
    risk 0.00cvss —epss 0.02

    calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

  • CVE-2015-0214Jun 1, 2015
    risk 0.00cvss —epss 0.02

    message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

  • CVE-2015-0213Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of…

  • CVE-2015-0212Jun 1, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.

  • CVE-2015-0211Jun 1, 2015
    risk 0.00cvss —epss 0.02

    mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote…

Page 8 of 13