Filtered by vendor Moodle
Subscriptions
Filtered by product Moodle
Subscriptions
Total
574 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-25630 | 1 Moodle | 1 Moodle | 2024-11-21 | 7.5 High |
A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. | ||||
CVE-2020-25629 | 1 Moodle | 1 Moodle | 2024-11-21 | 8.8 High |
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. | ||||
CVE-2020-25628 | 1 Moodle | 1 Moodle | 2024-11-21 | 6.1 Medium |
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. | ||||
CVE-2020-25627 | 1 Moodle | 1 Moodle | 2024-11-21 | 6.1 Medium |
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2. | ||||
CVE-2020-1756 | 1 Moodle | 1 Moodle | 2024-11-21 | 7.2 High |
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. | ||||
CVE-2020-1755 | 1 Moodle | 1 Moodle | 2024-11-21 | 5.3 Medium |
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. | ||||
CVE-2020-1754 | 1 Moodle | 1 Moodle | 2024-11-21 | 4.3 Medium |
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups. | ||||
CVE-2020-1692 | 1 Moodle | 1 Moodle | 2024-11-21 | 8.1 High |
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course. | ||||
CVE-2020-1691 | 1 Moodle | 1 Moodle | 2024-11-21 | 5.4 Medium |
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting. | ||||
CVE-2020-14322 | 1 Moodle | 1 Moodle | 2024-11-21 | 7.5 High |
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service. | ||||
CVE-2020-14321 | 1 Moodle | 1 Moodle | 2024-11-21 | 8.8 High |
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | ||||
CVE-2020-14320 | 1 Moodle | 1 Moodle | 2024-11-21 | 6.1 Medium |
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk. | ||||
CVE-2020-10738 | 1 Moodle | 1 Moodle | 2024-11-21 | 7.5 High |
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution. | ||||
CVE-2019-3852 | 1 Moodle | 1 Moodle | 2024-11-21 | N/A |
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities | ||||
CVE-2019-3851 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2024-11-21 | N/A |
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. | ||||
CVE-2019-3850 | 1 Moodle | 1 Moodle | 2024-11-21 | N/A |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits. | ||||
CVE-2019-3849 | 1 Moodle | 1 Moodle | 2024-11-21 | 8.8 High |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | ||||
CVE-2019-3848 | 1 Moodle | 1 Moodle | 2024-11-21 | 4.3 Medium |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.) | ||||
CVE-2019-3847 | 1 Moodle | 1 Moodle | 2024-11-21 | 4.8 Medium |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf. | ||||
CVE-2019-3810 | 1 Moodle | 1 Moodle | 2024-11-21 | 6.1 Medium |
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted. |