Show filters
543 Total Results
Displaying 81-90 of 543
Sort by:
Attacker Value
Unknown

CVE-2021-36568

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.
Attacker Value
Unknown

CVE-2020-1756

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
Attacker Value
Unknown

CVE-2020-1755

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Attacker Value
Unknown

CVE-2020-14322

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
Attacker Value
Unknown

CVE-2020-14321

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Attacker Value
Unknown

CVE-2020-14320

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
Attacker Value
Unknown

CVE-2020-1754

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Attacker Value
Unknown

CVE-2020-1691

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.
Attacker Value
Unknown

CVE-2022-35653

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
Attacker Value
Unknown

CVE-2022-35652

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.