Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  Security Vulnerabilities
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
CVSS Score
5.5
EPSS Score
0.013
Published
2024-06-20
Incorrect CSRF token checks resulted in multiple CSRF risks.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-06-18
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-06-18
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
5.9
EPSS Score
0.002
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.004
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-05-31
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
CVSS Score
4.3
EPSS Score
0.005
Published
2024-05-31
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-05-31
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVSS Score
8.8
EPSS Score
0.004
Published
2024-05-31


Contact Us

Shodan ® - All rights reserved