Search CVE reports


Toggle filters

111 – 120 of 607 results


CVE-2022-45152

Medium priority
Needs evaluation

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-45151

Medium priority
Needs evaluation

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-45150

Medium priority
Needs evaluation

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-45149

Medium priority
Needs evaluation

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-39369

Medium priority

Some fixes available 4 of 9

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...

3 affected packages

moodle, ocsinventory-server, php-cas

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Ignored Ignored
ocsinventory-server Not affected Fixed Not affected Not affected Ignored
php-cas Not affected Fixed Fixed Ignored Fixed
Show less packages

CVE-2022-2986

Medium priority
Needs evaluation

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-40316

Medium priority
Needs evaluation

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-40315

Medium priority
Needs evaluation

A limited SQL injection risk was identified in the "browse list of users" site administration page.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-40314

Medium priority
Needs evaluation

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-40313

Medium priority
Needs evaluation

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages