Search CVE reports
101 – 110 of 599 results
CVE-2023-23921
Medium priorityThe vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary...
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-39183
Medium priorityMoodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-45152
Medium priorityA blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL...
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-45151
Medium priorityThe stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code...
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-45150
Medium priorityA reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link...
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-45149
Medium priorityA vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they...
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-39369
Medium prioritySome fixes available 4 of 9
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...
3 affected packages
moodle, ocsinventory-server, php-cas
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | Not in release | Not in release | Not in release | Ignored | Ignored |
ocsinventory-server | Not affected | Fixed | Not affected | Not affected | Ignored |
php-cas | Not affected | Fixed | Fixed | Ignored | Fixed |
CVE-2022-2986
Medium priorityEnabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-40316
Medium priorityThe H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-40315
Medium priorityA limited SQL injection risk was identified in the "browse list of users" site administration page.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation | Needs evaluation |