Show filters
552 Total Results
Displaying 181-190 of 552
Sort by:
Attacker Value
Unknown
CVE-2019-3851
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
0
Attacker Value
Unknown
CVE-2019-3849
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
0
Attacker Value
Unknown
CVE-2019-3852
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
0
Attacker Value
Unknown
CVE-2019-3850
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
0
Attacker Value
Unknown
CVE-2019-3810
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
0
Attacker Value
Unknown
CVE-2019-3808
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
0
Attacker Value
Unknown
CVE-2019-3809
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
0
Attacker Value
Unknown
CVE-2019-6970
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Moodle 3.5.x before 3.5.4 allows SSRF.
0
Attacker Value
Unknown
CVE-2018-16854
Disclosure Date: November 26, 2018 (last updated November 27, 2024)
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.
0
Attacker Value
Unknown
CVE-2018-14631
Disclosure Date: September 17, 2018 (last updated November 27, 2024)
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.
0