Search CVE reports


Toggle filters

271 – 280 of 637 results


CVE-2018-1081

Medium priority
Needs evaluation

A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1045

Medium priority
Needs evaluation

In Moodle 3.x, there is XSS via a calendar event name.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1044

Medium priority
Needs evaluation

In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1043

Medium priority
Needs evaluation

In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1042

Medium priority
Needs evaluation

Moodle 3.x has Server Side Request Forgery in the filepicker.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2017-15110

Medium priority
Not affected

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle
Show less packages

CVE-2017-12157

Medium priority
Vulnerable

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-12156

Medium priority
Vulnerable

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7532

Medium priority
Vulnerable

In Moodle 3.x, course creators are able to change system default settings for courses.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7531

Medium priority
Vulnerable

In Moodle 3.3, the course overview block reveals activities in hidden courses.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Vulnerable
Show less packages