Search CVE reports
71 – 80 of 660 results
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | Not in release | Not in release | Not in release | Not affected |
Incorrect CSRF token checks resulted in multiple CSRF risks.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |