BDSA-2022-2073 |
|
Low |
Jul 26, 2022 |
Moodle is vulnerable to reflected cross-site scripting (XSS) in the LTI module. This could allow an unauthenticated attacker to execute arbitrary code
more...
Moodle is vulnerable to reflected cross-site scripting (XSS) in the LTI module. This could allow an unauthenticated attacker to execute arbitrary code on the victim's machine, which may steal sensitive information such as authentication tokens and user session cookies.
less...
|
|
BDSA-2022-2071 |
|
Medium |
Jul 26, 2022 |
Moodle is vulnerable to remote code execution (RCE) due to improper validation of GhostScript commands. This could allow an attacker to inject speciall
more...
Moodle is vulnerable to remote code execution (RCE) due to improper validation of GhostScript commands. This could allow an attacker to inject specially crafted PostScript code to compromise the system.
**Note:** Sites running GhostScript versions older than **9.50** are vulnerable.
less...
|
|
BDSA-2022-1396 |
|
Medium |
May 20, 2022 |
Moodle contains a login flaw when counting failed login attempts. This can allow an unauthenticated attacker to bypass the account lockout threshold an
more...
Moodle contains a login flaw when counting failed login attempts. This can allow an unauthenticated attacker to bypass the account lockout threshold and login to Moodle by means of a brute force attack.
less...
|
|
BDSA-2022-1395 |
|
Medium |
May 20, 2022 |
Moodle is vulnerable to SQL injection in the badge award criteria profile. This vulnerability could be used to read or modify Moodle's underlying datab
more...
Moodle is vulnerable to SQL injection in the badge award criteria profile. This vulnerability could be used to read or modify Moodle's underlying database and cause a high impact to confidentiality, integrity, and availability.
**Note**: in Moodle **4.0**, **3.11.6**, **3.10.10** and **3.9.13** access to this vulnerability is available to site administrators only. In earlier versions, access to the relevant capability is limited to teachers and managers by default.
less...
|
|
BDSA-2022-1394 |
|
Low |
May 19, 2022 |
Moodle is vulnerable to an information disclosure vulnerability. This could allow an attacker unauthorized access to the author information of some act
more...
Moodle is vulnerable to an information disclosure vulnerability. This could allow an attacker unauthorized access to the author information of some activities.
less...
|
|
BDSA-2022-1393 |
|
Low |
May 19, 2022 |
Moodle is vulnerable to information exposure due to improper enforcement of hidden user fields. This could allow an attacker to view user profile descr
more...
Moodle is vulnerable to information exposure due to improper enforcement of hidden user fields. This could allow an attacker to view user profile descriptions that have been set to be inaccessible.
less...
|
|
BDSA-2022-1392 |
|
Low |
May 19, 2022 |
Moodle is vulnerable to a stored cross-site scripting (XSS) vulnerability. This could allow an attacker to execute malicious JavaScript code in a victi
more...
Moodle is vulnerable to a stored cross-site scripting (XSS) vulnerability. This could allow an attacker to execute malicious JavaScript code in a victim's browser which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
BDSA-2021-4056 |
|
Low |
Jan 24, 2022 |
Moodle is vulnerable to an information leak via insufficient capability checks that allow teachers to download users outside of their courses.
Moodle is vulnerable to an information leak via insufficient capability checks that allow teachers to download users outside of their courses.
less...
|
|
BDSA-2021-3546 |
|
Medium |
Nov 23, 2021 |
Moodle is vulnerable to remote code execution (RCE). An attacker could exploit this by supplying a malformed backup file.
Moodle is vulnerable to remote code execution (RCE). An attacker could exploit this by supplying a malformed backup file.
less...
|
|
BDSA-2021-1888 |
|
Medium |
Jun 24, 2021 |
Moodle is vulnerable to command injection via the `aspellPath` parameter. A series of crafted HTTP requests can lead to command execution. An attacker
more...
Moodle is vulnerable to command injection via the `aspellPath` parameter. A series of crafted HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit the vulnerability.
This vulnerability does not require that the spellchecker plugin is enabled
less...
|
|