Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2023-03-06 CVE-2021-36396 Server-Side Request Forgery (SSRF) vulnerability in Moodle
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
network
low complexity
moodle CWE-918
7.5
2023-02-17 CVE-2023-23921 Cross-site Scripting vulnerability in Moodle
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters.
network
low complexity
moodle CWE-79
6.1
2023-02-17 CVE-2023-23922 Cross-site Scripting vulnerability in Moodle
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search.
network
low complexity
moodle CWE-79
6.1
2023-02-17 CVE-2023-23923 Unspecified vulnerability in Moodle
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference.
network
low complexity
moodle
8.2
2023-01-12 CVE-2022-39183 Open Redirect vulnerability in Moodle Saml Authentication
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
network
low complexity
moodle CWE-601
6.1
2022-11-25 CVE-2022-45152 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle.
network
low complexity
moodle fedoraproject CWE-918
critical
9.1
2022-11-23 CVE-2022-45149 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL.
network
low complexity
moodle fedoraproject CWE-352
5.4
2022-11-23 CVE-2022-45150 Cross-site Scripting vulnerability in multiple products
A reflected cross-site scripting vulnerability was discovered in Moodle.
network
low complexity
moodle fedoraproject CWE-79
6.1
2022-11-23 CVE-2022-45151 Cross-site Scripting vulnerability in multiple products
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields.
network
low complexity
moodle fedoraproject CWE-79
5.4
2022-10-06 CVE-2022-2986 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
network
low complexity
moodle CWE-352
8.8