CVEs (625)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. |
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. |
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized. |
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. |
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. |
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered. |
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the...Show more |
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroo...Show more |
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle we...Show more |
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle we...Show more |
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. |
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk. |
The referrer URL used by MFA required additional sanitizing, rather than being used directly. |
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. |
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation. |
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to. |
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you k...Show more |
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. |
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). |
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |