Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-5545 Exposure of Resource to Wrong Sphere vulnerability in multiple products
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
network
low complexity
moodle fedoraproject CWE-668
5.3
2023-11-09 CVE-2023-5546 Cross-site Scripting vulnerability in multiple products
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
network
low complexity
moodle redhat fedoraproject CWE-79
5.4
2023-11-09 CVE-2023-5547 Cross-site Scripting vulnerability in multiple products
The course upload preview contained an XSS risk for users uploading unsafe data.
network
low complexity
moodle redhat fedoraproject CWE-79
6.1
2023-11-09 CVE-2023-5548 Insufficient Verification of Data Authenticity vulnerability in multiple products
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
network
low complexity
moodle fedoraproject CWE-345
5.3
2023-11-09 CVE-2023-5549 Improper Privilege Management vulnerability in multiple products
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
network
low complexity
moodle fedoraproject CWE-269
5.3
2023-11-09 CVE-2023-5550 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
network
low complexity
moodle fedoraproject
critical
9.8
2023-11-09 CVE-2023-5551 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
local
low complexity
moodle fedoraproject
3.3
2023-10-29 CVE-2023-46858 Cross-site Scripting vulnerability in Moodle 4.3.0
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher.
network
low complexity
moodle CWE-79
5.4
2023-06-22 CVE-2023-35131 Cross-site Scripting vulnerability in Moodle
Content on the groups page required additional sanitizing to prevent an XSS risk.
network
low complexity
moodle CWE-79
6.1
2023-06-22 CVE-2023-35132 SQL Injection vulnerability in Moodle
A limited SQL injection risk was identified on the Mnet SSO access control page.
network
low complexity
moodle CWE-89
6.3