Search CVE reports
261 – 270 of 672 results
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the...
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
2 affected packages
glpi, moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glpi | — | — | — | — | Not in release |
| moodle | — | — | — | — | Not affected |
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
2 affected packages
glpi, moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glpi | — | — | — | — | Not in release |
| moodle | — | — | — | — | Not affected |
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
3 affected packages
gallery2, moodle, smarty
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| gallery2 | — | — | — | — | — |
| moodle | — | — | — | — | — |
| smarty | — | — | — | — | — |
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough Versions 2.2 to 2.2.1+ affected.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | — |
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ affected.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | — |
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | — |
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | — |
Moodle before 2.2.2: Overview report allows users to see hidden courses Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.
1 affected package
moodle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | — | — | — | — |