Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 08.08.2025 19:41:25

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

  • EPSS 0.11%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 08.08.2025 19:40:46

Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

  • EPSS 0.11%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 08.08.2025 19:40:08

Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

  • EPSS 0.11%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 08.08.2025 19:38:31

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

  • EPSS 0.04%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 08.08.2025 19:37:24

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

  • EPSS 0.13%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 11.08.2025 14:55:22

The question bank filter required additional sanitizing to prevent a reflected XSS risk.

  • EPSS 0.08%
  • Veröffentlicht 24.02.2025 20:15:33
  • Zuletzt bearbeitet 07.08.2025 00:06:02

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

  • EPSS 0.2%
  • Veröffentlicht 20.11.2024 11:15:05
  • Zuletzt bearbeitet 02.06.2025 15:33:57

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

  • EPSS 0.22%
  • Veröffentlicht 20.11.2024 11:15:05
  • Zuletzt bearbeitet 02.06.2025 15:34:48

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

  • EPSS 0.09%
  • Veröffentlicht 20.11.2024 11:15:05
  • Zuletzt bearbeitet 02.06.2025 15:35:23

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic ha...