CVE-2023-28330
- EPSS 0.4%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:54:51
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVE-2021-36402
- EPSS 0.24%
- Veröffentlicht 06.03.2023 23:15:10
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVE-2021-36403
- EPSS 0.21%
- Veröffentlicht 06.03.2023 23:15:10
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVE-2021-36397
- EPSS 0.57%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:32
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36398
- EPSS 0.74%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:33
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36399
- EPSS 0.68%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:33
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36400
- EPSS 0.2%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 18:15:34
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36401
- EPSS 0.13%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36392
- EPSS 0.46%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:40
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36393
- EPSS 30.44%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:40
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.