Moodle

Moodle

631 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 25.04.2025 14:43:18
  • Zuletzt bearbeitet 24.06.2025 15:59:32

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

  • EPSS 0.3%
  • Veröffentlicht 25.04.2025 14:43:15
  • Zuletzt bearbeitet 24.06.2025 15:59:22

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

  • EPSS 0.32%
  • Veröffentlicht 25.04.2025 14:43:12
  • Zuletzt bearbeitet 24.06.2025 15:59:15

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

  • EPSS 0.23%
  • Veröffentlicht 25.04.2025 14:43:10
  • Zuletzt bearbeitet 24.06.2025 15:59:06

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

Medienbericht
  • EPSS 1.39%
  • Veröffentlicht 25.04.2025 14:43:07
  • Zuletzt bearbeitet 29.04.2025 13:52:28

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

Medienbericht
  • EPSS 1.39%
  • Veröffentlicht 25.04.2025 14:43:04
  • Zuletzt bearbeitet 29.04.2025 13:52:28

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

  • EPSS 0.3%
  • Veröffentlicht 25.04.2025 14:43:02
  • Zuletzt bearbeitet 29.04.2025 13:52:28

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

  • EPSS 0.14%
  • Veröffentlicht 25.04.2025 14:42:59
  • Zuletzt bearbeitet 16.06.2025 21:03:13

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

  • EPSS 0.2%
  • Veröffentlicht 25.04.2025 14:42:56
  • Zuletzt bearbeitet 29.04.2025 13:52:28

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the ...

  • EPSS 0.21%
  • Veröffentlicht 25.04.2025 14:42:54
  • Zuletzt bearbeitet 29.04.2025 13:52:28

A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.