Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Moodle
(Moodle)Repositories |
• https://github.com/moodle/moodle
• https://github.com/tinymce/tinymce_spellchecker_php |
#Vulnerabilities | 521 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-03-31 | CVE-2019-14880 | A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise. | Moodle | N/A | ||
2020-03-18 | CVE-2019-14881 | A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed. | Moodle | N/A | ||
2020-01-07 | CVE-2019-14879 | A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable). | Moodle | N/A | ||
2020-03-18 | CVE-2019-14883 | A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token. | Moodle | N/A | ||
2020-03-18 | CVE-2019-14884 | A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages. | Moodle | N/A | ||
2020-03-18 | CVE-2019-14882 | A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page. | Moodle | N/A | ||
2012-07-17 | CVE-2012-0797 | The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token. | Moodle | N/A | ||
2019-11-14 | CVE-2012-1168 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. | Fedora, Moodle, Enterprise_linux | N/A | ||
2019-11-14 | CVE-2012-1156 | Moodle before 2.2.2 has users' private files included in course backups | Fedora, Moodle, Enterprise_linux | N/A | ||
2019-11-14 | CVE-2012-1155 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | Debian_linux, Fedora, Moodle, Enterprise_linux | N/A |