Vulnerabilities > Moodle > Moodle > 2.1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-18 | CVE-2024-48896 | Information Exposure Through an Error Message vulnerability in Moodle A vulnerability was found in Moodle. | 4.3 |
2024-11-18 | CVE-2024-48897 | Incorrect Authorization vulnerability in Moodle A vulnerability was found in Moodle. | 4.3 |
2024-11-18 | CVE-2024-48898 | Missing Authorization vulnerability in Moodle A vulnerability was found in Moodle. | 4.3 |
2024-11-18 | CVE-2024-48901 | Incorrect Authorization vulnerability in Moodle A vulnerability was found in Moodle. | 4.3 |
2024-06-18 | CVE-2024-38276 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products Incorrect CSRF token checks resulted in multiple CSRF risks. | 8.8 |
2024-02-12 | CVE-2024-1439 | Unspecified vulnerability in Moodle Inadequate access control in Moodle LMS. | 3.3 |
2023-11-09 | CVE-2023-5539 | Code Injection vulnerability in multiple products A remote code execution risk was identified in the Lesson activity. | 8.8 |
2023-11-09 | CVE-2023-5540 | Code Injection vulnerability in multiple products A remote code execution risk was identified in the IMSCP activity. | 8.8 |
2023-11-09 | CVE-2023-5545 | Exposure of Resource to Wrong Sphere vulnerability in multiple products H5P metadata automatically populated the author with the user's username, which could be sensitive information. | 5.3 |
2023-11-09 | CVE-2023-5548 | Insufficient Verification of Data Authenticity vulnerability in multiple products Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. | 5.3 |