Filtered by vendor Moodle
Subscriptions
Total
566 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-45150 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-04-25 | 6.1 Medium |
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages. | ||||
CVE-2022-45149 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-04-25 | 5.4 Medium |
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks. | ||||
CVE-2024-25982 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-04-24 | 4.3 Medium |
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | ||||
CVE-2024-43437 | 1 Moodle | 1 Moodle | 2025-04-23 | 5.4 Medium |
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. | ||||
CVE-2024-43439 | 1 Moodle | 1 Moodle | 2025-04-23 | 5.4 Medium |
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | ||||
CVE-2017-7532 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.x, course creators are able to change system default settings for courses. | ||||
CVE-2017-7491 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting. | ||||
CVE-2017-7490 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing. | ||||
CVE-2017-7531 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.3, the course overview block reveals activities in hidden courses. | ||||
CVE-2017-2644 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.x, XSS can occur via evidence of prior learning. | ||||
CVE-2017-2641 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | ||||
CVE-2017-2645 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning. | ||||
CVE-2017-2576 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums. | ||||
CVE-2017-2643 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.2.x, global search displays user names for unauthenticated users. | ||||
CVE-2017-2578 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.x, there is XSS in the assignment submission page. | ||||
CVE-2017-7298 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. | ||||
CVE-2016-8644 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. | ||||
CVE-2016-8643 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | ||||
CVE-2017-2642 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
Moodle 3.x has user fullname disclosure on the user preferences page. | ||||
CVE-2017-12156 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback. |