Search CVE reports


Toggle filters

131 – 140 of 659 results


CVE-2021-27131

Medium priority
Not affected

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not affected
Show less packages

CVE-2023-30944

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-30943

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40208

Medium priority
Needs evaluation

In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28336

Medium priority
Needs evaluation

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28335

Medium priority
Needs evaluation

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28334

Medium priority
Needs evaluation

Authenticated users were able to enumerate other users' names via the learning plans page.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28333

Medium priority
Needs evaluation

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28332

Medium priority
Needs evaluation

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2023-28331

Medium priority
Needs evaluation

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages