Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  >> 1.3.4  Security Vulnerabilities
Moodle before 2.2.2 has users' private files included in course backups
CVSS Score
7.5
EPSS Score
0.012
Published
2019-11-14
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVSS Score
8.2
EPSS Score
0.022
Published
2019-11-14
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
CVSS Score
4.0
EPSS Score
0.002
Published
2019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
CVSS Score
4.0
EPSS Score
0.002
Published
2019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
CVSS Score
4.0
EPSS Score
0.002
Published
2019-07-31
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-06-26
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
CVSS Score
5.4
EPSS Score
0.013
Published
2019-03-27
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
CVSS Score
4.3
EPSS Score
0.001
Published
2019-03-26
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
CVSS Score
6.3
EPSS Score
0.004
Published
2019-03-26


Contact Us

Shodan ® - All rights reserved