Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Filtered by product Moodle
Total 512 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-1170 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-02-04 5.0 MEDIUM 7.5 HIGH
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
CVE-2012-1157 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
CVE-2019-3847 1 Moodle 1 Moodle 2024-02-04 3.5 LOW 4.8 MEDIUM
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
CVE-2019-3852 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
CVE-2019-3849 1 Moodle 1 Moodle 2024-02-04 6.5 MEDIUM 8.8 HIGH
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
CVE-2019-10187 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
CVE-2019-10189 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
CVE-2019-6970 1 Moodle 1 Moodle 2024-02-04 6.0 MEDIUM 7.5 HIGH
Moodle 3.5.x before 3.5.4 allows SSRF.
CVE-2019-3808 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 5.4 MEDIUM
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
CVE-2019-3810 1 Moodle 1 Moodle 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
CVE-2019-10134 1 Moodle 1 Moodle 2024-02-04 4.3 MEDIUM 3.7 LOW
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
CVE-2019-3809 1 Moodle 1 Moodle 2024-02-04 7.5 HIGH 10.0 CRITICAL
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
CVE-2019-10154 1 Moodle 1 Moodle 2024-02-04 5.0 MEDIUM 7.5 HIGH
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVE-2019-3851 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
CVE-2019-3848 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
CVE-2019-3850 1 Moodle 1 Moodle 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
CVE-2019-10186 1 Moodle 1 Moodle 2024-02-04 6.8 MEDIUM 8.8 HIGH
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
CVE-2019-10188 1 Moodle 1 Moodle 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
CVE-2019-10133 1 Moodle 1 Moodle 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
CVE-2018-16854 1 Moodle 1 Moodle 2024-02-04 6.8 MEDIUM 8.8 HIGH
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.