Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2025-26533

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
An SQL injection risk was identified in the module list filter within course search.
0
Attacker Value
Unknown

CVE-2025-26532

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
0
Attacker Value
Unknown

CVE-2025-26531

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
0
Attacker Value
Unknown

CVE-2025-26530

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown

CVE-2025-26529

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown

CVE-2025-26528

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
0
Attacker Value
Unknown

CVE-2025-26527

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
0
Attacker Value
Unknown

CVE-2025-26526

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
0
Attacker Value
Unknown

CVE-2025-26525

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
0
Attacker Value
Unknown

CVE-2020-36633

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this issue. The name of the patch is cd18d8b1afe464ae6626832496f4e070bac4c58f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216879.