Search CVE reports


Toggle filters

171 – 180 of 672 results


CVE-2023-23921

Medium priority
Needs evaluation

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-39183

Medium priority
Needs evaluation

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-45152

Medium priority
Needs evaluation

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-45151

Medium priority
Needs evaluation

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-45150

Medium priority
Needs evaluation

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-45149

Medium priority
Needs evaluation

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-39369

Medium priority

Some fixes available 4 of 5

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...

3 affected packages

moodle, ocsinventory-server, php-cas

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — Not in release Not in release Not in release Ignored
ocsinventory-server — Not affected Fixed Not affected Not affected
php-cas — Not affected Fixed Fixed Ignored
Show less packages

CVE-2022-2986

Medium priority
Needs evaluation

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40316

Medium priority
Needs evaluation

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40315

Medium priority
Needs evaluation

A limited SQL injection risk was identified in the "browse list of users" site administration page.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — Not in release Not in release Needs evaluation
Show less packages