Show filters
1,862 Total Results
Displaying 71-80 of 1,862
Sort by:
Attacker Value
Unknown
CVE-2023-5549
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
0
Attacker Value
Unknown
CVE-2023-5548
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
0
Attacker Value
Unknown
CVE-2023-5547
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
The course upload preview contained an XSS risk for users uploading unsafe data.
0
Attacker Value
Unknown
CVE-2023-5546
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown
CVE-2023-5545
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
0
Attacker Value
Unknown
CVE-2023-5544
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
0
Attacker Value
Unknown
CVE-2023-5542
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
0
Attacker Value
Unknown
CVE-2023-5540
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
0
Attacker Value
Unknown
CVE-2023-5539
Disclosure Date: November 09, 2023 (last updated April 19, 2024)
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
0
Attacker Value
Unknown
CVE-2023-5824
Disclosure Date: November 03, 2023 (last updated October 24, 2024)
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
0