Show filters
542 Total Results
Displaying 11-20 of 542
Sort by:
Attacker Value
Unknown
CVE-2024-38273
Disclosure Date: June 18, 2024 (last updated June 19, 2024)
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
0
Attacker Value
Unknown
CVE-2024-34008
Disclosure Date: May 31, 2024 (last updated July 19, 2024)
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2024-33996
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
0
Attacker Value
Unknown
CVE-2024-25983
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
0
Attacker Value
Unknown
CVE-2024-25982
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2024-25981
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
0
Attacker Value
Unknown
CVE-2024-25980
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
0
Attacker Value
Unknown
CVE-2024-25979
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
The URL parameters accepted by forum search were not limited to the allowed parameters.
0
Attacker Value
Unknown
CVE-2024-25978
Disclosure Date: February 19, 2024 (last updated January 24, 2025)
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
0
Attacker Value
Unknown
CVE-2024-1439
Disclosure Date: February 12, 2024 (last updated October 12, 2024)
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
0