Vulnerabilities > Moodle > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2021-20283 Missing Authorization vulnerability in multiple products
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
network
low complexity
moodle fedoraproject CWE-862
4.3
2021-03-15 CVE-2021-20282 Incorrect Authorization vulnerability in multiple products
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
network
low complexity
moodle fedoraproject CWE-863
5.3
2021-03-15 CVE-2021-20281 Incorrect Authorization vulnerability in multiple products
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
network
low complexity
moodle fedoraproject CWE-863
5.3
2021-03-15 CVE-2021-20280 Cross-site Scripting vulnerability in multiple products
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
network
low complexity
moodle fedoraproject CWE-79
5.4
2021-03-15 CVE-2021-20279 Cross-site Scripting vulnerability in multiple products
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
network
low complexity
moodle fedoraproject CWE-79
5.4
2021-01-28 CVE-2021-20185 Allocation of Resources Without Limits or Throttling vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.
network
low complexity
moodle CWE-770
5.3
2021-01-28 CVE-2021-20184 Improper Validation of Integrity Check Value vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
network
low complexity
moodle CWE-354
4.0
2021-01-28 CVE-2021-20183 Cross-site Scripting vulnerability in Moodle
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.
network
moodle CWE-79
4.3
2020-12-09 CVE-2020-25627 Cross-site Scripting vulnerability in Moodle 3.9.0/3.9.1/3.9.2
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk.
network
moodle CWE-79
4.3
2020-12-08 CVE-2020-25631 Cross-site Scripting vulnerability in Moodle
A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page.
network
moodle CWE-79
4.3