CVE-2023-28336
- EPSS 0.26%
- Veröffentlicht 23.03.2023 21:15:20
- Zuletzt bearbeitet 21.11.2024 07:54:52
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
CVE-2023-1402
- EPSS 0.26%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:39:07
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
CVE-2023-28329
- EPSS 0.32%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:54:51
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
CVE-2023-28330
- EPSS 0.56%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:54:51
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVE-2021-36402
- EPSS 0.47%
- Veröffentlicht 06.03.2023 23:15:10
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVE-2021-36403
- EPSS 0.41%
- Veröffentlicht 06.03.2023 23:15:10
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVE-2021-36397
- EPSS 0.27%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:32
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36398
- EPSS 0.91%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:33
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36399
- EPSS 0.91%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 19:15:33
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36400
- EPSS 0.38%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 18:15:34
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.