Show filters
542 Total Results
Displaying 61-70 of 542
Sort by:
Attacker Value
Unknown

CVE-2021-36393

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
Attacker Value
Unknown

CVE-2021-36392

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
Attacker Value
Unknown

CVE-2023-23923

Disclosure Date: February 17, 2023 (last updated April 19, 2024)
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
Attacker Value
Unknown

CVE-2023-23922

Disclosure Date: February 17, 2023 (last updated April 19, 2024)
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
Attacker Value
Unknown

CVE-2023-23921

Disclosure Date: February 17, 2023 (last updated April 19, 2024)
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
Attacker Value
Unknown

CVE-2022-39183

Disclosure Date: January 12, 2023 (last updated October 08, 2023)
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
Attacker Value
Unknown

CVE-2020-36633

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this issue. The name of the patch is cd18d8b1afe464ae6626832496f4e070bac4c58f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216879.
Attacker Value
Unknown

CVE-2022-45152

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Attacker Value
Unknown

CVE-2022-45151

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Attacker Value
Unknown

CVE-2022-45150

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.