Vulnerabilities
Vulnerable Software
Moodle:  Security Vulnerabilities
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
CVSS Score
5.6
EPSS Score
0.006
Published
2023-05-02
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
CVSS Score
6.5
EPSS Score
0.175
Published
2023-05-02
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-03-24
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVSS Score
6.1
EPSS Score
0.006
Published
2023-03-23
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
CVSS Score
6.1
EPSS Score
0.005
Published
2023-03-23
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
CVSS Score
9.8
EPSS Score
0.007
Published
2023-03-23
Authenticated users were able to enumerate other users' names via the learning plans page.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-03-23
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
CVSS Score
8.8
EPSS Score
0.003
Published
2023-03-23
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
CVSS Score
4.3
EPSS Score
0.002
Published
2023-03-23
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
CVSS Score
4.3
EPSS Score
0.002
Published
2023-03-23


Contact Us

Shodan ® - All rights reserved