Search CVE reports
41 – 50 of 607 results
CVE-2024-34000
Medium priorityID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-33999
Medium priorityThe referrer URL used by MFA required additional sanitizing, rather than being used directly.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-33998
Medium priorityInsufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-33997
Medium priorityAdditional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-33996
Medium priorityIncorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-28593
Medium priority** DISPUTED ** The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If...
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-29374
Medium priorityA Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-25983
Medium priorityInsufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-25982
Medium priorityThe link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-25981
Medium prioritySeparate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Needs evaluation | Needs evaluation |