6.5

CVSS3.1

CVE-2024-34005 - moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_dโ€ฆ

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

๐Ÿ“… Published: May 31, 2024, 8:27 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 3:43 p.m.

6.5

CVSS3.1

CVE-2024-34004 - moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_wโ€ฆ

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

๐Ÿ“… Published: May 31, 2024, 8:23 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 3:43 p.m.

5.9

CVSS3.1

CVE-2024-34003 - moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_wโ€ฆ

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

๐Ÿ“… Published: May 31, 2024, 8:19 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 3:40 p.m.

6.5

CVSS3.1

CVE-2024-34002 - moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_fโ€ฆ

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

๐Ÿ“… Published: May 31, 2024, 8:15 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 3:39 p.m.

8.4

CVSS3.1

CVE-2024-34001 - moodle: CSRF risk in admin preset tool management of presets

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

๐Ÿ“… Published: May 31, 2024, 8:06 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-34000 - moodle: stored XSS in lesson overview report via user ID number

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

๐Ÿ“… Published: May 31, 2024, 8:01 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:48 p.m.

9.8

CVSS3.1

CVE-2024-33999 - moodle: unsafe direct use of $_SERVER['HTTP_REFERER'] in admin/tool/mfa/index.php

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

๐Ÿ“… Published: May 31, 2024, 7:53 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:47 p.m.

5.4

CVSS3.1

CVE-2024-33998 - moodle: stored XSS via user's name on participants page when opening some options

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

๐Ÿ“… Published: May 31, 2024, 7:46 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:47 p.m.

6.1

CVSS3.1

CVE-2024-33997 - moodle: stored XSS risk when editing another user's equation in equation editor

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

๐Ÿ“… Published: May 31, 2024, 7:38 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:41 p.m.

6.2

CVSS3.1

CVE-2024-33996 - moodle: broken access control when setting calendar event type

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

๐Ÿ“… Published: May 31, 2024, 7:29 p.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:41 p.m.
Total resulsts: 349182
Page 9615 of 34,919
ยซ previous page ยป next page
Filters