Search CVE reports
141 – 150 of 637 results
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they...
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
Some fixes available 4 of 9
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...
3 affected packages
php-cas, ocsinventory-server, moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php-cas | Not affected | Fixed | Fixed | Ignored |
ocsinventory-server | Not affected | Fixed | Not affected | Not affected |
moodle | Not in release | Not in release | Not in release | Ignored |
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
A limited SQL injection risk was identified in the "browse list of users" site administration page.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | Not in release | Not in release | Needs evaluation |
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | — | — | Needs evaluation |
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | — | — | Needs evaluation |
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
1 affected package
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
moodle | — | — | — | Needs evaluation |