CVEs (625)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2: Overview report allows users to see hidden courses |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 14, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle before 2.2.2 has users' private files included in course backups |
4Debian FedoraprojectMoodle+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment. |
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz. |
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to. |
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool. |
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. |
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded. |
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScrip...Show more |
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Mar 26, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening wi...Show more |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. |
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users...Show more |