CVE-2024-33998
- EPSS 0.79%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:47:37
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
CVE-2024-33999
- EPSS 0.46%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:47:47
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
CVE-2024-28593
- EPSS 0.11%
- Veröffentlicht 22.03.2024 15:15:15
- Zuletzt bearbeitet 01.05.2025 15:05:31
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can us...
CVE-2024-29374
- EPSS 0.23%
- Veröffentlicht 21.03.2024 19:15:09
- Zuletzt bearbeitet 01.05.2025 15:05:13
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2024-25980
- EPSS 0.13%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:47:04
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25981
- EPSS 0.16%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:45:12
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25982
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:42:27
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-25983
- EPSS 0.14%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 17:37:14
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25978
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:38
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25979
- EPSS 0.13%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:30
The URL parameters accepted by forum search were not limited to the allowed parameters.