CVE-2024-34001
- EPSS 0.32%
- Veröffentlicht 31.05.2024 20:15:10
- Zuletzt bearbeitet 30.05.2025 16:48:09
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-33996
- EPSS 0.18%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:41:36
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
CVE-2024-33997
- EPSS 1%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:41:45
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
CVE-2024-33998
- EPSS 1.4%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:47:37
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
CVE-2024-33999
- EPSS 0.81%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:47:47
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
CVE-2024-28593
- EPSS 0.11%
- Veröffentlicht 22.03.2024 15:15:15
- Zuletzt bearbeitet 01.05.2025 15:05:31
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can us...
CVE-2024-29374
- EPSS 0.3%
- Veröffentlicht 21.03.2024 19:15:09
- Zuletzt bearbeitet 01.05.2025 15:05:13
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2024-25980
- EPSS 0.17%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:47:04
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25981
- EPSS 0.27%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:45:12
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25982
- EPSS 0.38%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:42:27
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.