Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 18.06.2024 20:15:13
  • Zuletzt bearbeitet 30.04.2025 23:35:59

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • EPSS 0.45%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:39:00

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local fi...

  • EPSS 0.18%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:40:54

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local fi...

  • EPSS 0.31%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:43:44

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file i...

  • EPSS 0.45%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 01.05.2025 15:43:22

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a...

  • EPSS 0.42%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 30.05.2025 16:48:15

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

  • EPSS 0.69%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 30.05.2025 16:48:34

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

  • EPSS 0.36%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 25.03.2025 17:15:55

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

  • EPSS 0.14%
  • Veröffentlicht 31.05.2024 21:15:09
  • Zuletzt bearbeitet 30.05.2025 16:48:46

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

  • EPSS 0.28%
  • Veröffentlicht 31.05.2024 20:15:10
  • Zuletzt bearbeitet 30.05.2025 16:48:06

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.