Moodle — CWE-Other

All FrameworksMoodleCWE-Other

45 CVEs categorized as CWE-Other — Uncategorized in Moodle.

CVE-2022-29862022
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CVE-2021-406952021
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
CVE-2021-406942021
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
CVE-2021-406932021
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
CVE-2021-406922021
Insufficient capability checks made it possible for teachers to download users outside of their courses.
CVE-2021-406912021
A session hijack risk was identified in the Shibboleth authentication plugin.
CVE-2021-21809HIGH2021
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
CVE-2019-3852MEDIUM2019
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
CVE-2019-3851MEDIUM2019
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
CVE-2019-3850MEDIUM2019
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more su…
CVE-2018-11372018
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
CVE-2018-11362018
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other…
CVE-2018-11352018
An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.
CVE-2018-11342018
An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.
CVE-2018-11332018
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
CVE-2018-10452018
In Moodle 3.x, there is XSS via a calendar event name.
CVE-2018-10442018
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.
CVE-2018-10432018
In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.
CVE-2018-10422018
Moodle 3.x has Server Side Request Forgery in the filepicker.
CVE-2017-74912017
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVE-2017-74902017
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
CVE-2017-74892017
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
CVE-2017-26452017
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVE-2017-26442017
In Moodle 3.x, XSS can occur via evidence of prior learning.
CVE-2017-26432017
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVE-2017-26412017
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVE-2017-25782017
In Moodle 3.x, there is XSS in the assignment submission page.
CVE-2017-25762017
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
CVE-2017-151102017
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
CVE-2017-121572017
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
CVE-2017-121562017
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
CVE-2016-86442016
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
CVE-2016-86432016
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
CVE-2016-86422016
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2016-70382016
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVE-2012-11702012
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
CVE-2012-11692012
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
CVE-2012-11682012
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2012-11612012
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
CVE-2012-11602012
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
CVE-2012-11592012
Moodle before 2.2.2: Overview report allows users to see hidden courses
CVE-2012-11582012
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
CVE-2012-11572012
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
CVE-2012-11562012
Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-11552012
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to