Search CVE reports


Toggle filters

101 – 110 of 607 results


CVE-2021-36397

Medium priority
Needs evaluation

In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36396

Medium priority
Needs evaluation

In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36395

Medium priority
Needs evaluation

In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36394

Medium priority
Needs evaluation

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36393

Medium priority
Needs evaluation

In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36392

Medium priority
Needs evaluation

In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-23923

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-23922

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-23921

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-39183

Medium priority
Needs evaluation

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages