Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2022-03-11 CVE-2021-32473 Unspecified vulnerability in Moodle
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
network
low complexity
moodle
5.3
2022-03-11 CVE-2021-32474 SQL Injection vulnerability in Moodle
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host.
network
low complexity
moodle CWE-89
7.2
2022-03-11 CVE-2021-32475 Cross-site Scripting vulnerability in Moodle
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
network
low complexity
moodle CWE-79
5.4
2022-03-11 CVE-2021-32476 Allocation of Resources Without Limits or Throttling vulnerability in Moodle
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits.
network
low complexity
moodle CWE-770
7.5
2022-03-11 CVE-2021-32477 Missing Authorization vulnerability in Moodle
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default).
network
low complexity
moodle CWE-862
4.3
2022-03-11 CVE-2021-32478 Cross-site Scripting vulnerability in Moodle
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks.
network
low complexity
moodle CWE-79
6.1
2022-01-25 CVE-2022-0332 SQL Injection vulnerability in Moodle
A flaw was found in Moodle in versions 3.11 to 3.11.4.
network
low complexity
moodle CWE-89
critical
9.8
2022-01-25 CVE-2022-0333 Incorrect Authorization vulnerability in Moodle
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions.
network
low complexity
moodle CWE-863
3.8
2022-01-25 CVE-2022-0334 Exposure of Resource to Wrong Sphere vulnerability in Moodle
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions.
network
low complexity
moodle CWE-668
4.3
2022-01-25 CVE-2022-0335 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions.
network
low complexity
moodle CWE-352
8.8