Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  >> 4.1.0  Security Vulnerabilities
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-11-07
Incorrect CSRF token checks resulted in multiple CSRF risks.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-06-18
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-06-18
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-06-18
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-06-18
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-06-18
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
5.9
EPSS Score
0.002
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.004
Published
2024-05-31
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-05-31


Contact Us

Shodan ® - All rights reserved