moodle/moodle
Moodle - the world's open source learning platform
Security Advisories for moodle/moodle in packagist
Moderate
10 days ago
Moodle's error handling leads to sensitive information disclosure
packagist
moodle/moodle
Moderate
10 days ago
Moodle sends quiz-related messages to inactive/suspended users
packagist
moodle/moodle
Moderate
10 days ago
Moodle course access permissions are not properly checked in course_output_fragment_course_overview
packagist
moodle/moodle
Moderate
4 months ago
Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter
packagist
moodle/moodle
High
6 months ago
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
packagist
moodle/moodle
Moderate
6 months ago
Moodle has reflected Cross-site Scripting risk in policy tool
packagist
moodle/moodle
Moderate
6 months ago
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
packagist
moodle/moodle
Low
6 months ago
Moodle has a CSRF risk in user tours manager that allows tour duplication
packagist
moodle/moodle
Low
6 months ago
Moodle has a CSRF risk in Brickfield tool's analysis request action
packagist
moodle/moodle
High
6 months ago
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
packagist
moodle/moodle
Low
6 months ago
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
packagist
moodle/moodle
Moderate
6 months ago
Moodle has an IDOR in messaging web service which allows access to some user details
packagist
moodle/moodle
Moderate
6 months ago
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
packagist
moodle/moodle
Moderate
6 months ago
Moodle's AJAX section delete does not respect course_can_delete_section()
packagist
moodle/moodle
Moderate
6 months ago
Moodle shows hidden grades to users without permission on some grade reports
packagist
moodle/moodle
Moderate
6 months ago
Moodle makes some user data available before completing second factor with MFA enabled
packagist
moodle/moodle
Moderate
6 months ago
Moodle self enrollment available before completing second factor with MFA enabled
packagist
moodle/moodle
Moderate
6 months ago
Moodle reveals student identities through assignment submissions search on anonymous submissions
packagist
moodle/moodle
Low
8 months ago
Moodle has an IDOR in badges allows disabling of arbitrary badges
packagist
moodle/moodle
High
8 months ago
Moodle has a SQL injection risk in course search module list filter
packagist
moodle/moodle
Low
8 months ago
Moodle allows teachers to evade trusttext config when restoring glossary entries
packagist
moodle/moodle
Moderate
8 months ago
Moodle's feedback response viewing and deletions did not respect Separate Groups mode
packagist
moodle/moodle
Moderate
8 months ago
Moodle's non-searchable tags can still be discovered on the tag search page and in the tags block
packagist
moodle/moodle
Moderate
12 months ago
Moodle Lesson activity password bypass through PHP loose comparison
packagist
moodle/moodle
Moderate
12 months ago
Moodle allows users to retrieve information they did not have permission to access
packagist
moodle/moodle
Moderate
12 months ago
moodle: Some users can delete audiences of other reports
packagist
moodle/moodle
Low
12 months ago
Moodle's user/power level management inconsistent with suspended users
packagist
moodle/moodle
Low
12 months ago
Moodle authorization headers preserved between "emulated redirects"
packagist
moodle/moodle
Low
12 months ago
Moodle admin presets export tool includes some secrets that should not be exported
packagist
moodle/moodle
Low
12 months ago
Moodle has user information visibility control issues in gradebook reports
packagist
moodle/moodle
Moderate
12 months ago
Moodle vulnerable to site administration SQL injection via XMLDB editor
packagist
moodle/moodle
Moderate
12 months ago
Moodle vulnerable to cache poisoning via injection into storage
packagist
moodle/moodle
Moderate
12 months ago
Moodle's IDOR in badges allows deletion of arbitrary badges
packagist
moodle/moodle
Moderate
12 months ago
Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users
packagist
moodle/moodle
Moderate
12 months ago
Moodle LFI vulnerability when restoring malformed block backups
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle stored XSS via calendar's event title when deleting the event
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle BigBlueButton web service leaks meeting joining information
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle uses the same key for QR login and auto-login
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle HTTP authorization header is preserved between "emulated redirects"
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle Unsanitized HTML in site log for config_log_created
packagist
moodle/moodle
High
over 1 year ago
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
packagist
moodle/moodle
High
over 1 year ago
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
packagist
moodle/moodle
High
over 1 year ago
Moodle CSRF risk in admin preset tool management of presets
packagist
moodle/moodle
Moderate
over 1 year ago
Moodle broken access control when setting calendar event type
packagist
moodle/moodle
Moderate
almost 2 years ago
Moodle Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability
packagist
moodle/moodle
Low
almost 2 years ago
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
packagist
moodle/moodle
Moderate
almost 2 years ago
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
packagist
moodle/moodle