Search CVE reports
101 – 110 of 607 results
CVE-2021-36397
Medium priorityIn Moodle, insufficient capability checks meant message deletions were not limited to the current user.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36396
Medium priorityIn Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36395
Medium priorityIn Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36394
Medium priorityIn Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36393
Medium priorityIn Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36392
Medium priorityIn Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-23923
Medium priorityThe vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain...
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-23922
Medium priorityThe vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script...
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-23921
Medium priorityThe vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary...
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-39183
Medium priorityMoodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |