Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  >> 3.0.0  Security Vulnerabilities
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
CVSS Score
6.5
EPSS Score
0.014
Published
2023-11-09
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
CVSS Score
4.7
EPSS Score
0.019
Published
2023-11-09
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
CVSS Score
3.3
EPSS Score
0.005
Published
2023-11-09
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CVSS Score
4.7
EPSS Score
0.019
Published
2023-11-09
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
CVSS Score
6.3
EPSS Score
0.008
Published
2023-06-22
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
CVSS Score
7.5
EPSS Score
0.008
Published
2023-06-22
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVSS Score
5.3
EPSS Score
0.005
Published
2023-03-06
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVSS Score
5.3
EPSS Score
0.005
Published
2023-03-06
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVSS Score
5.3
EPSS Score
0.006
Published
2023-03-06
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVSS Score
5.3
EPSS Score
0.005
Published
2023-03-06


Contact Us

Shodan ® - All rights reserved