Search CVE reports
131 – 140 of 599 results
CVE-2022-30600
Medium priorityA flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-30599
Medium priorityA flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-30598
Low priorityA flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-30597
Low priorityA flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-30596
Medium priorityA flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-0984
Medium priorityUsers with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-0985
Medium priorityInsufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2022-0983
Medium priorityAn SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2021-32478
Medium priorityThe redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |
CVE-2021-32477
Low priorityThe last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
1 affected packages
moodle
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
moodle | — | — | — | Needs evaluation | Needs evaluation |