Show filters
750 Total Results
Displaying 61-70 of 750
Sort by:
Attacker Value
Unknown
CVE-2022-35653
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
0
Attacker Value
Unknown
CVE-2022-35651
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.
0
Attacker Value
Unknown
CVE-2022-2078
Disclosure Date: June 30, 2022 (last updated November 29, 2024)
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.
0
Attacker Value
Unknown
CVE-2022-1708
Disclosure Date: June 07, 2022 (last updated February 23, 2025)
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus, if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability.
0
Attacker Value
Unknown
CVE-2022-30600
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
0
Attacker Value
Unknown
CVE-2022-30599
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
0
Attacker Value
Unknown
CVE-2022-30598
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
0
Attacker Value
Unknown
CVE-2022-30597
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
0
Attacker Value
Unknown
CVE-2022-30596
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2022-1706
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
0