Search CVE reports


Toggle filters

301 – 310 of 672 results


CVE-2018-1136

Medium priority
Needs evaluation

An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1135

Medium priority
Needs evaluation

An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1134

Medium priority
Needs evaluation

An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1133

Medium priority
Needs evaluation

An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1082

Medium priority
Needs evaluation

A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1081

Medium priority
Needs evaluation

A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1045

Medium priority
Needs evaluation

In Moodle 3.x, there is XSS via a calendar event name.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1044

Medium priority
Needs evaluation

In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1043

Medium priority
Needs evaluation

In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2018-1042

Medium priority
Needs evaluation

Moodle 3.x has Server Side Request Forgery in the filepicker.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Needs evaluation
Show less packages