Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 05.08.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:11:18

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • EPSS 7.53%
  • Veröffentlicht 25.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:26

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exp...

  • EPSS 0.44%
  • Veröffentlicht 25.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:26

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal...

  • EPSS 0.28%
  • Veröffentlicht 25.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:26

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary H...

  • EPSS 0.38%
  • Veröffentlicht 25.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:26

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitr...

  • EPSS 81.09%
  • Veröffentlicht 25.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:26

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute...

  • EPSS 0.47%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:02:59

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • EPSS 0.45%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

  • EPSS 1.95%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • EPSS 6.85%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.