Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 29.09.2022 03:15:14
  • Zuletzt bearbeitet 21.11.2024 06:24:34

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

  • EPSS 0.49%
  • Veröffentlicht 29.09.2022 03:15:14
  • Zuletzt bearbeitet 21.11.2024 06:24:34

Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

  • EPSS 0.33%
  • Veröffentlicht 29.09.2022 03:15:14
  • Zuletzt bearbeitet 21.11.2024 06:24:35

It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 13.09.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:13:50

In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting S...

  • EPSS 0.75%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:03:00

In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

  • EPSS 39.4%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:03:00

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

  • EPSS 0.55%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:03:00

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

  • EPSS 0.13%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:11:19

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

  • EPSS 0.74%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:11:19

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

  • EPSS 0.71%
  • Veröffentlicht 05.08.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:11:10

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.