Moodle

Moodle

601 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 20.11.2024 11:15:05
  • Last modified 02.06.2025 15:36:03

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

  • EPSS 0.24%
  • Published 18.11.2024 12:15:18
  • Last modified 20.11.2024 14:47:12

A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name fo...

  • EPSS 0.2%
  • Published 18.11.2024 12:15:18
  • Last modified 20.11.2024 14:48:25

A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

  • EPSS 0.2%
  • Published 18.11.2024 12:15:18
  • Last modified 20.11.2024 14:46:16

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

  • EPSS 0.2%
  • Published 18.11.2024 12:15:18
  • Last modified 20.11.2024 14:45:10

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

  • EPSS 0.21%
  • Published 13.11.2024 15:15:07
  • Last modified 13.06.2025 00:33:54

A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

  • EPSS 0.65%
  • Published 11.11.2024 16:15:14
  • Last modified 23.04.2025 21:26:17

A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

  • EPSS 0.41%
  • Published 11.11.2024 13:15:04
  • Last modified 01.05.2025 16:08:09

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

  • EPSS 0.21%
  • Published 11.11.2024 13:15:04
  • Last modified 01.05.2025 16:08:59

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to re...

  • EPSS 0.41%
  • Published 11.11.2024 13:15:04
  • Last modified 01.05.2025 16:09:18

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.