Search CVE reports
91 – 100 of 607 results
CVE-2023-28331
Medium priorityContent output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-28330
Medium priorityInsufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-28329
Medium priorityInsufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-1402
Medium priorityThe course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36403
Medium priorityIn Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36402
Medium priorityIn Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36401
Medium priorityIn Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36400
Medium priorityIn Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36399
Medium priorityIn Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2021-36398
Medium priorityIn moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |