CVE-2021-36401
- EPSS 0.23%
- Veröffentlicht 06.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 18:15:35
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36392
- EPSS 0.81%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:40
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36393
- EPSS 26.77%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:40
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36394
- EPSS 11.65%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 06.03.2025 16:15:37
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36395
- EPSS 0.55%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 07.03.2025 19:15:32
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36396
- EPSS 3.06%
- Veröffentlicht 06.03.2023 21:15:10
- Zuletzt bearbeitet 05.03.2025 16:15:35
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
CVE-2023-23921
- EPSS 0.29%
- Veröffentlicht 17.02.2023 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:47:06
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code ...
CVE-2023-23922
- EPSS 0.29%
- Veröffentlicht 17.02.2023 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:47:06
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's brow...
CVE-2023-23923
- EPSS 0.32%
- Veröffentlicht 17.02.2023 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:47:06
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to othe...
CVE-2022-45152
- EPSS 0.18%
- Veröffentlicht 25.11.2022 19:15:12
- Zuletzt bearbeitet 29.04.2025 15:15:52
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in...