CVE-2021-40693
- EPSS 0.25%
- Veröffentlicht 29.09.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 06:24:34
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
CVE-2021-40694
- EPSS 0.49%
- Veröffentlicht 29.09.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 06:24:34
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
CVE-2021-40695
- EPSS 0.33%
- Veröffentlicht 29.09.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 06:24:35
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
CVE-2021-36568
- EPSS 0.43%
- Veröffentlicht 13.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:50
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting S...
CVE-2020-14320
- EPSS 0.75%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:03:00
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
CVE-2020-14321
- EPSS 39.4%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:03:00
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
CVE-2020-14322
- EPSS 0.55%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:03:00
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
CVE-2020-1755
- EPSS 0.13%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:11:19
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
CVE-2020-1756
- EPSS 0.74%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:11:19
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
CVE-2020-1691
- EPSS 0.71%
- Veröffentlicht 05.08.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:11:10
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.