Show filters
549 Total Results
Displaying 111-120 of 549
Sort by:
Attacker Value
Unknown

CVE-2022-0333

Disclosure Date: January 25, 2022 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
Attacker Value
Unknown

CVE-2022-0332

Disclosure Date: January 25, 2022 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
Attacker Value
Unknown

CVE-2021-43560

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Attacker Value
Unknown

CVE-2021-43559

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
Attacker Value
Unknown

CVE-2021-43558

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
Attacker Value
Unknown

CVE-2021-3943

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
Attacker Value
Unknown

CVE-2021-21809

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
Attacker Value
Unknown

CVE-2021-32244

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.
Attacker Value
Unknown

CVE-2019-14827

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.
Attacker Value
Unknown

CVE-2019-14829

Disclosure Date: March 19, 2021 (last updated February 22, 2025)
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.