CVE-2024-43428
- EPSS 0.04%
- Published 07.11.2024 14:15:15
- Last modified 01.05.2025 16:01:48
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
CVE-2024-43431
- EPSS 0.28%
- Published 07.11.2024 14:15:15
- Last modified 01.05.2025 16:02:42
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
CVE-2024-37674
- EPSS 1.83%
- Published 20.06.2024 18:15:12
- Last modified 13.06.2025 14:33:53
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
CVE-2024-38276
- EPSS 0.15%
- Published 18.06.2024 20:15:14
- Last modified 26.03.2025 14:15:31
Incorrect CSRF token checks resulted in multiple CSRF risks.
CVE-2024-38277
- EPSS 0.14%
- Published 18.06.2024 20:15:14
- Last modified 07.08.2025 17:24:28
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
CVE-2024-38273
- EPSS 0.15%
- Published 18.06.2024 20:15:13
- Last modified 07.08.2025 16:43:09
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
CVE-2024-38274
- EPSS 0.56%
- Published 18.06.2024 20:15:13
- Last modified 07.08.2025 17:23:59
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
CVE-2024-38275
- EPSS 0.56%
- Published 18.06.2024 20:15:13
- Last modified 30.04.2025 23:35:59
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
CVE-2024-34002
- EPSS 0.38%
- Published 31.05.2024 21:15:09
- Last modified 01.05.2025 15:39:00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local fi...
CVE-2024-34003
- EPSS 0.14%
- Published 31.05.2024 21:15:09
- Last modified 01.05.2025 15:40:54
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local fi...