Search CVE reports


Toggle filters

21 – 30 of 607 results


CVE-2024-43434

Medium priority
Needs evaluation

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-43431

Medium priority
Needs evaluation

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-43428

Medium priority
Needs evaluation

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-43426

Medium priority
Needs evaluation

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-43425

Medium priority
Needs evaluation

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-37674

Medium priority
Needs evaluation

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-38277

Medium priority
Not affected

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-38276

Medium priority
Needs evaluation

Incorrect CSRF token checks resulted in multiple CSRF risks.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-38275

Medium priority
Needs evaluation

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-38274

Medium priority
Needs evaluation

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages