Vulnerabilities > Moodle > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-28 CVE-2021-20185 Allocation of Resources Without Limits or Throttling vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.
network
low complexity
moodle CWE-770
5.3
2021-01-28 CVE-2021-20186 Unspecified vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
network
low complexity
moodle
5.4
2021-01-28 CVE-2021-20184 Unspecified vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
network
low complexity
moodle
4.3
2021-01-28 CVE-2021-20183 Unspecified vulnerability in Moodle
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.
network
low complexity
moodle
5.4
2020-12-09 CVE-2020-25627 Unspecified vulnerability in Moodle 3.9.0/3.9.1
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk.
network
low complexity
moodle
6.1
2020-12-08 CVE-2020-25631 Unspecified vulnerability in Moodle
A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page.
network
low complexity
moodle
6.1
2020-12-08 CVE-2020-25628 Unspecified vulnerability in Moodle
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk.
network
low complexity
moodle
6.1
2020-11-19 CVE-2020-25703 Information Exposure vulnerability in multiple products
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden.
network
low complexity
moodle fedoraproject CWE-200
5.3
2020-11-19 CVE-2020-25702 Cross-site Scripting vulnerability in multiple products
In Moodle, it was possible to include JavaScript when re-naming content bank items.
network
low complexity
moodle fedoraproject CWE-79
6.1
2020-11-19 CVE-2020-25701 Incorrect Authorization vulnerability in multiple products
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method.
network
low complexity
moodle fedoraproject CWE-863
5.3