Search CVE reports
321 – 330 of 660 results
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Vulnerable |
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Vulnerable |
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Vulnerable |
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Vulnerable |
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Vulnerable |
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | Not affected |
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | Ignored |
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then...
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | Ignored |
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then...
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | Ignored |
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor...
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | Not in release | Not in release | Not in release | Not affected |