Vulnerabilities > Moodle > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-28330 Unspecified vulnerability in Moodle
Insufficient sanitizing in backup resulted in an arbitrary file read risk.
network
low complexity
moodle
6.5
2023-03-23 CVE-2023-28331 Cross-site Scripting vulnerability in Moodle
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
network
low complexity
moodle CWE-79
6.1
2023-03-23 CVE-2023-28332 Cross-site Scripting vulnerability in Moodle
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
network
low complexity
moodle CWE-79
6.1
2023-03-23 CVE-2023-28334 Authorization Bypass Through User-Controlled Key vulnerability in Moodle
Authenticated users were able to enumerate other users' names via the learning plans page.
network
low complexity
moodle CWE-639
4.3
2023-03-23 CVE-2023-28336 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
network
low complexity
moodle fedoraproject CWE-668
4.3
2023-03-06 CVE-2021-36402 Unspecified vulnerability in Moodle
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
network
low complexity
moodle
5.3
2023-03-06 CVE-2021-36403 Unspecified vulnerability in Moodle
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
network
low complexity
moodle
5.3
2023-03-06 CVE-2021-36397 Unspecified vulnerability in Moodle
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
network
low complexity
moodle
5.3
2023-03-06 CVE-2021-36398 Cross-site Scripting vulnerability in Moodle 3.11.0
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
network
low complexity
moodle CWE-79
5.4
2023-03-06 CVE-2021-36399 Cross-site Scripting vulnerability in Moodle 3.11.0
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
network
low complexity
moodle CWE-79
5.4