Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

81 – 90 of 599 results


CVE-2023-28333

Medium priority
Needs evaluation

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28332

Medium priority
Needs evaluation

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28331

Medium priority
Needs evaluation

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28330

Medium priority
Needs evaluation

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28329

Medium priority
Needs evaluation

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-1402

Medium priority
Needs evaluation

The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36403

Medium priority
Needs evaluation

In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36402

Medium priority
Needs evaluation

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36401

Medium priority
Needs evaluation

In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-36400

Medium priority
Needs evaluation

In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

1 affected packages

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
moodle Not in release Not in release Needs evaluation Needs evaluation
Show less packages