Show filters
542 Total Results
Displaying 1-10 of 542
Sort by:
Attacker Value
Unknown
CVE-2019-10189
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
1
Attacker Value
Unknown
CVE-2024-48901
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
0
Attacker Value
Unknown
CVE-2024-48898
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
0
Attacker Value
Unknown
CVE-2024-48897
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
0
Attacker Value
Unknown
CVE-2024-48896
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
0
Attacker Value
Unknown
CVE-2024-34312
Disclosure Date: June 24, 2024 (last updated August 09, 2024)
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
0
Attacker Value
Unknown
CVE-2024-38277
Disclosure Date: June 18, 2024 (last updated June 19, 2024)
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
0
Attacker Value
Unknown
CVE-2024-38276
Disclosure Date: June 18, 2024 (last updated August 09, 2024)
Incorrect CSRF token checks resulted in multiple CSRF risks.
0
Attacker Value
Unknown
CVE-2024-38275
Disclosure Date: June 18, 2024 (last updated June 19, 2024)
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
0
Attacker Value
Unknown
CVE-2024-38274
Disclosure Date: June 18, 2024 (last updated June 19, 2024)
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
0