Moodle

Moodle

631 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 06.11.2024 21:15:06
  • Zuletzt bearbeitet 04.09.2025 16:08:00

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when prepar...

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 01.07.2024 13:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Exploit
  • EPSS 3.62%
  • Veröffentlicht 20.06.2024 18:15:12
  • Zuletzt bearbeitet 13.06.2025 14:33:53

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

  • EPSS 0.27%
  • Veröffentlicht 18.06.2024 20:15:14
  • Zuletzt bearbeitet 26.03.2025 14:15:31

Incorrect CSRF token checks resulted in multiple CSRF risks.

  • EPSS 0.19%
  • Veröffentlicht 18.06.2024 20:15:14
  • Zuletzt bearbeitet 07.08.2025 17:24:28

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

  • EPSS 0.2%
  • Veröffentlicht 18.06.2024 20:15:13
  • Zuletzt bearbeitet 07.08.2025 16:43:09

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

  • EPSS 0.99%
  • Veröffentlicht 18.06.2024 20:15:13
  • Zuletzt bearbeitet 07.08.2025 17:23:59

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

  • EPSS 0.55%
  • Veröffentlicht 18.06.2024 20:15:13
  • Zuletzt bearbeitet 30.04.2025 23:35:59

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • EPSS 0.45%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:39:00

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local fi...

  • EPSS 0.18%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:40:54

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local fi...