Show filters
549 Total Results
Displaying 111-120 of 549
Sort by:
Attacker Value
Unknown
CVE-2022-0333
Disclosure Date: January 25, 2022 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
0
Attacker Value
Unknown
CVE-2022-0332
Disclosure Date: January 25, 2022 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
0
Attacker Value
Unknown
CVE-2021-43560
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
0
Attacker Value
Unknown
CVE-2021-43559
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2021-43558
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown
CVE-2021-3943
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
0
Attacker Value
Unknown
CVE-2021-21809
Disclosure Date: June 23, 2021 (last updated February 22, 2025)
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
0
Attacker Value
Unknown
CVE-2021-32244
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.
0
Attacker Value
Unknown
CVE-2019-14827
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.
0
Attacker Value
Unknown
CVE-2019-14829
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
0