Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 31.05.2024 20:15:10
  • Zuletzt bearbeitet 30.05.2025 16:48:09

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

  • EPSS 0.18%
  • Veröffentlicht 31.05.2024 20:15:09
  • Zuletzt bearbeitet 30.05.2025 16:41:36

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

  • EPSS 1%
  • Veröffentlicht 31.05.2024 20:15:09
  • Zuletzt bearbeitet 30.05.2025 16:41:45

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

  • EPSS 1.4%
  • Veröffentlicht 31.05.2024 20:15:09
  • Zuletzt bearbeitet 30.05.2025 16:47:37

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

  • EPSS 0.81%
  • Veröffentlicht 31.05.2024 20:15:09
  • Zuletzt bearbeitet 30.05.2025 16:47:47

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

  • EPSS 0.11%
  • Veröffentlicht 22.03.2024 15:15:15
  • Zuletzt bearbeitet 01.05.2025 15:05:31

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can us...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 21.03.2024 19:15:09
  • Zuletzt bearbeitet 01.05.2025 15:05:13

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

  • EPSS 0.17%
  • Veröffentlicht 19.02.2024 17:15:09
  • Zuletzt bearbeitet 23.01.2025 16:47:04

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

  • EPSS 0.27%
  • Veröffentlicht 19.02.2024 17:15:09
  • Zuletzt bearbeitet 23.01.2025 16:45:12

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

  • EPSS 0.38%
  • Veröffentlicht 19.02.2024 17:15:09
  • Zuletzt bearbeitet 23.01.2025 16:42:27

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.