ALT-PU-2021-3335-2
Closed vulnerabilities
BDU:2021-06184
Уязвимость системы управления Moodle, связанная с ошибками управления генерации кода, позволяющая нарушителю выполнить произвольный код
BDU:2021-06185
Уязвимость системы управления Moodle, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить привилегии
BDU:2021-06186
Уязвимость системы управления Moodle, связанная с непринятием мер по защите структуры веб-страниц, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)
BDU:2021-06190
Уязвимость функции «delete related badge» системы управления Moodle, связанная с межсайтовыми фольсификациями запросов, позволяющая нарушителю осуществить CSRF-атаку
Modified: 2024-11-21
CVE-2021-3943
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
Modified: 2024-11-21
CVE-2021-40691
A session hijack risk was identified in the Shibboleth authentication plugin.
Modified: 2024-11-21
CVE-2021-40692
Insufficient capability checks made it possible for teachers to download users outside of their courses.
Modified: 2024-11-21
CVE-2021-40693
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
Modified: 2024-11-21
CVE-2021-40694
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
Modified: 2024-11-21
CVE-2021-40695
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
Modified: 2024-11-21
CVE-2021-43558
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
Modified: 2024-11-21
CVE-2021-43559
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
Modified: 2024-11-21
CVE-2021-43560
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Modified: 2024-04-24
GHSA-2jxg-mv2m-j4r7
Moodle type juggling vulnerability
Modified: 2023-07-11
GHSA-3jrj-x6cj-97cp
Moodle contains CSRF vulnerability
Modified: 2023-07-11
GHSA-8jhp-2gcr-qw96
Moodle vulnerable to RCE via unsafe deserialization
Modified: 2024-04-24
GHSA-92vh-mr2w-j2cr
Moodle Improper Authentication
Modified: 2024-04-24
GHSA-g39c-mccf-rxjv
Moodle Insecure direct object reference (IDOR) in a calendar web service
Modified: 2024-04-24
GHSA-gp4w-f57r-9rx3
Moodle Exposure of Sensitive Information to an Unauthorized Actor
Modified: 2024-04-24
GHSA-m37g-mwcg-7j7v
Moodle Improper Encoding or Escaping of Output
Modified: 2022-06-17
GHSA-wpfp-q843-v772
Cross-site Scripting in moodle
Modified: 2024-04-24
GHSA-wr6q-xv23-rfq9
Moodle Incorrect Authorization
