Search CVE reports


Toggle filters

221 – 230 of 637 results


CVE-2019-14884

Medium priority
Needs evaluation

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2019-14883

Medium priority
Not affected

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not affected
Show less packages

CVE-2019-14882

Medium priority
Not affected

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not affected
Show less packages

CVE-2019-14881

Medium priority
Needs evaluation

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2020-1692

Medium priority
Needs evaluation

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2019-18210

Low priority
Needs evaluation

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2019-14879

Medium priority
Needs evaluation

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2012-1105

Medium priority
Ignored

An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.

2 affected packages

glpi, moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release
moodle Not affected
Show less packages

CVE-2012-1104

Medium priority
Ignored

A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.

2 affected packages

glpi, moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release
moodle Not affected
Show less packages

CVE-2011-1028

Medium priority
Ignored

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

3 affected packages

gallery2, moodle, smarty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gallery2
moodle
smarty
Show less packages