Releases2
Frequency21 hours 43 minutes
Last Release
Downloads3.61K
Moodle Webservice Client in Rust.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
<= 4.0.06.1 MEDIUM

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

< 4.5.9, >= 5.0.0, < 5.0.5, >= 5.1.0, < 5.1.26.5 MEDIUM

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.

< 4.5.9, >= 5.0.0, < 5.0.5, >= 5.1.0, < 5.1.27.2 HIGH

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

< 4.5.9, >= 5.0.0, < 5.0.5, >= 5.1.0, < 5.1.27.2 HIGH

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

< 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.04.3 MEDIUM

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

< 4.1.22, >= 4.4.0, < 4.4.12, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.05.4 MEDIUM

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.05.4 MEDIUM

A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through specially crafted links. Successful exploitation could lead to information disclosure or arbitrary client-side script execution within the user's browser.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.07.5 HIGH

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.03.5 LOW

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.06.1 MEDIUM

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.07.3 HIGH

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

>= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.07.3 HIGH

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

< 4.1.22, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.08.1 HIGH

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

< 4.1.22, >= 4.4.0, < 4.4.12, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, = 5.1.08.8 HIGH

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.

= 3.10.37.2 HIGH

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

>= 4.1.0, < 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.35.4 MEDIUM

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

>= 4.1.0, < 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.34.3 MEDIUM

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

>= 4.1.0, < 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.37.5 HIGH

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

>= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.35.4 MEDIUM

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

>= 5.0.0, < 5.0.35.3 MEDIUM

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

>= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.35.3 MEDIUM

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

>= 4.1.0, < 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.34.3 MEDIUM

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

>= 4.5.0, < 4.5.7, >= 5.0.0, < 5.0.34.3 MEDIUM

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

>= 5.0.0, < 5.0.34.3 MEDIUM

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.

>= 3.0.0, <= 3.11.184.2 MEDIUM

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.184.3 MEDIUM

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.184.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.184.3 MEDIUM

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.185.4 MEDIUM

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.188.8 HIGH

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.188.8 HIGH

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

>= 4.5.0, < 4.5.44.3 MEDIUM

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.188.8 HIGH

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

>= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.3.123.1 LOW

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.184.3 MEDIUM

A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.183.5 LOW

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4, < 4.1.184.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.44.3 MEDIUM

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.47.1 HIGH

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

>= 4.5.0, < 4.5.3, < 4.1.17, >= 4.3.0, < 4.3.11, >= 4.4.0, < 4.4.75.3 MEDIUM

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

>= 4.5.0, < 4.5.37.5 HIGH

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

>= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.44.3 MEDIUM

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.28.1 HIGH

An SQL injection risk was identified in the module list filter within course search.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.23.1 LOW

Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

>= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.28.3 HIGH

The question bank filter required additional sanitizing to prevent a reflected XSS risk.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.23.1 LOW

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.28.3 HIGH

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.23.4 LOW

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.25.3 MEDIUM

Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.26.5 MEDIUM

Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

>= 4.1.0, < 4.1.16, >= 4.3.0, < 4.3.10, >= 4.4.0, < 4.4.6, >= 4.5.0, < 4.5.28.6 HIGH

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

>= 4.4.0, < 4.4.44.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

>= 4.2.0, < 4.2.10, >= 4.3.0, < 4.3.7, >= 4.4.0, < 4.4.3, < 4.1.136.5 MEDIUM

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

>= 4.2.0, < 4.2.10, >= 4.3.0, < 4.3.7, >= 4.4.0, < 4.4.3, < 4.1.135.4 MEDIUM

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.

>= 4.2.0, < 4.2.10, >= 4.3.0, < 4.3.7, >= 4.4.0, < 4.4.3, < 4.1.137.5 HIGH

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

>= 4.4.0, <= 4.4.4, >= 4.3.0, <= 4.3.8, >= 4.2.0, <= 4.2.11, <= 4.1.144.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

>= 4.4.0, <= 4.4.4, >= 4.3.0, <= 4.3.8, >= 4.2.0, <= 4.2.11, <= 4.1.144.3 MEDIUM

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

>= 4.4.0, <= 4.4.4, >= 4.3.0, <= 4.3.8, >= 4.2.0, <= 4.2.11, <= 4.1.144.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

>= 4.4.0, <= 4.4.4, >= 4.3.0, <= 4.3.8, >= 4.2.0, <= 4.2.11, <= 4.1.144.3 MEDIUM

A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.

>= 4.4.0, < 4.4.44.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.4 MEDIUM

A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.4 MEDIUM

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

>= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.3 MEDIUM

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.3 MEDIUM

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

>= 4.4.0, < 4.4.25.3 MEDIUM

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.3 MEDIUM

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.23.7 LOW

A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.25.3 MEDIUM

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

>= 4.1.0, < 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.5 HIGH

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

>= 4.1.0, < 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.2 HIGH

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.28.1 HIGH

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.5 HIGH

A flaw was found in moodle. A local file may include risks when restoring block backups.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.5 HIGH

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.7 HIGH

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

>= 4.1.0, < 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.27.5 HIGH

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

< 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.28.1 HIGH

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

= 3.10.05.5 MEDIUM

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

>= 4.1.0, < 4.1.11, >= 4.2.0, < 4.2.8, >= 4.3.0, < 4.3.5, = 4.4.05.4 MEDIUM

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

>= 4.2.0, < 4.2.8, >= 4.3.0, < 4.3.5, = 4.4.0, < 4.1.108.8 HIGH

Incorrect CSRF token checks resulted in multiple CSRF risks.

>= 4.2.0, < 4.2.8, >= 4.3.0, < 4.3.5, = 4.4.0, < 4.1.117.5 HIGH

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

>= 4.1.0, < 4.1.11, >= 4.2.0, < 4.2.8, >= 4.3.0, < 4.3.5, = 4.4.06.1 MEDIUM

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

>= 4.1.0, < 4.1.11, >= 4.2.0, < 4.2.8, >= 4.3.0, < 4.3.5, = 4.4.05.4 MEDIUM

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

>= 4.3.0, < 4.3.47.5 HIGH

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

>= 4.1, < 4.1.10, >= 4.2, < 4.2.7, >= 4.0, < 4.3.48.8 HIGH

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

>= 4.3.0, < 4.3.48.8 HIGH

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.44.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.46.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.46.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.45.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

< 4.1.10, >= 4.2.0, < 4.2.7, > 4.3.0, < 4.3.46.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.48.4 HIGH

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.44.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

>= 4.3.0, < 4.3.49.8 CRITICAL

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.45.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.46.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

< 4.1.10, >= 4.2.0, < 4.2.7, >= 4.3.0, < 4.3.46.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

= 4.3.35.4 MEDIUM

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

= 3.10.96.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.93.5 LOW

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.94.3 MEDIUM

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.94.3 MEDIUM

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.94.3 MEDIUM

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.95.3 MEDIUM

The URL parameters accepted by forum search were not limited to the allowed parameters.

>= 4.3.0, < 4.3.3, >= 4.2.0, < 4.2.6, >= 4.1.0, < 4.1.97.5 HIGH

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

<= 4.2.116.5 MEDIUM

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.113.3 LOW

When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.243.3 LOW

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.243.3 LOW

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.243.3 LOW

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, >= 3.9.0, < 3.9.243.3 LOW

The course upload preview contained an XSS risk for users uploading unsafe data.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.114.3 MEDIUM

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.246.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.243.3 LOW

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, >= 3.9.0, < 3.9.246.5 MEDIUM

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

= 4.2.23.3 LOW

Students in "Only see own membership" groups could see other students in the group, which should be hidden.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, >= 3.9.0, < 3.9.243.3 LOW

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.244.7 MEDIUM

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

>= 4.2.0, < 4.2.3, >= 4.1.0, < 4.1.6, >= 4.0.0, < 4.0.11, >= 3.11.0, < 3.11.17, < 3.9.244.7 MEDIUM

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

= 4.3.05.4 MEDIUM

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."