Search CVE reports


Toggle filters

141 – 150 of 637 results


CVE-2022-45149

Medium priority
Needs evaluation

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2022-39369

Medium priority

Some fixes available 4 of 9

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...

3 affected packages

php-cas, ocsinventory-server, moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-cas Not affected Fixed Fixed Ignored
ocsinventory-server Not affected Fixed Not affected Not affected
moodle Not in release Not in release Not in release Ignored
Show less packages

CVE-2022-2986

Medium priority
Needs evaluation

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40316

Medium priority
Needs evaluation

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40315

Medium priority
Needs evaluation

A limited SQL injection risk was identified in the "browse list of users" site administration page.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40314

Medium priority
Needs evaluation

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40313

Medium priority
Needs evaluation

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Needs evaluation
Show less packages

CVE-2021-40695

Medium priority
Needs evaluation

It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Needs evaluation
Show less packages

CVE-2021-40694

Medium priority
Needs evaluation

Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Needs evaluation
Show less packages

CVE-2021-40693

Medium priority
Needs evaluation

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Needs evaluation
Show less packages