Show filters
542 Total Results
Displaying 71-80 of 542
Sort by:
Attacker Value
Unknown

CVE-2022-45149

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.
Attacker Value
Unknown

CVE-2022-2986

Disclosure Date: October 06, 2022 (last updated February 24, 2025)
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
Attacker Value
Unknown

CVE-2022-40316

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
Attacker Value
Unknown

CVE-2022-40315

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Attacker Value
Unknown

CVE-2022-40314

Disclosure Date: September 30, 2022 (last updated October 08, 2023)
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
Attacker Value
Unknown

CVE-2022-40313

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
Attacker Value
Unknown

CVE-2021-40695

Disclosure Date: September 29, 2022 (last updated October 08, 2023)
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
Attacker Value
Unknown

CVE-2021-40694

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
Attacker Value
Unknown

CVE-2021-40693

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
Attacker Value
Unknown

CVE-2021-40692

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
Insufficient capability checks made it possible for teachers to download users outside of their courses.