CVE-2024-34004
- EPSS 0.26%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 01.05.2025 15:43:44
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file i...
CVE-2024-34005
- EPSS 0.38%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 01.05.2025 15:43:22
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a...
CVE-2024-34006
- EPSS 0.36%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 30.05.2025 16:48:15
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
CVE-2024-34007
- EPSS 0.39%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 30.05.2025 16:48:34
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVE-2024-34008
- EPSS 0.3%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 25.03.2025 17:15:55
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2024-34009
- EPSS 0.11%
- Veröffentlicht 31.05.2024 21:15:09
- Zuletzt bearbeitet 30.05.2025 16:48:46
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
CVE-2024-34000
- EPSS 0.38%
- Veröffentlicht 31.05.2024 20:15:10
- Zuletzt bearbeitet 30.05.2025 16:48:06
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
CVE-2024-34001
- EPSS 0.27%
- Veröffentlicht 31.05.2024 20:15:10
- Zuletzt bearbeitet 30.05.2025 16:48:09
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-33996
- EPSS 0.18%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:41:36
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
CVE-2024-33997
- EPSS 0.76%
- Veröffentlicht 31.05.2024 20:15:09
- Zuletzt bearbeitet 30.05.2025 16:41:45
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.