Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

61 – 70 of 582 results


CVE-2023-28336

Medium priority
Needs evaluation

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28335

Medium priority
Needs evaluation

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28334

Medium priority
Needs evaluation

Authenticated users were able to enumerate other users' names via the learning plans page.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28333

Medium priority
Needs evaluation

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28332

Medium priority
Needs evaluation

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28331

Medium priority
Needs evaluation

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28330

Medium priority
Needs evaluation

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28329

Medium priority
Needs evaluation

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-1402

Medium priority
Needs evaluation

The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36403

Medium priority
Needs evaluation

In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages