Moodle
moodle
627 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. |
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. |
The URL parameters accepted by forum search were not limited to the allowed parameters. |
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. |
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file inc...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The course upload preview contained an XSS risk for users uploading unsafe data. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. |
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their cours...Show more |