Search CVE reports


Toggle filters

91 – 100 of 646 results


CVE-2023-5543

Medium priority
Needs evaluation

When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5551

Medium priority
Needs evaluation

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5550

Medium priority
Needs evaluation

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5549

Medium priority
Needs evaluation

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5548

Medium priority
Needs evaluation

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5547

Medium priority
Needs evaluation

The course upload preview contained an XSS risk for users uploading unsafe data.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5546

Medium priority
Needs evaluation

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5545

Medium priority
Needs evaluation

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5544

Medium priority
Needs evaluation

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2023-5542

Medium priority
Needs evaluation

Students in "Only see own membership" groups could see other students in the group, which should be hidden.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages