Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.27%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:33

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • EPSS 1.23%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:33

Moodle before 2.2.2 has users' private files included in course backups

  • EPSS 2.22%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:34

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • EPSS 0.31%
  • Veröffentlicht 31.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:36

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

  • EPSS 0.17%
  • Veröffentlicht 31.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:36

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

  • EPSS 0.17%
  • Veröffentlicht 31.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:36

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

  • EPSS 0.17%
  • Veröffentlicht 31.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:36

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.

  • EPSS 0.15%
  • Veröffentlicht 26.06.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:29

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

  • EPSS 0.18%
  • Veröffentlicht 26.06.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:29

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

  • EPSS 0.24%
  • Veröffentlicht 26.06.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:31

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.