Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-34033: WordPress Ajax Pagination and Infinite Scroll plugin <= 2.0.1 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Malinky Ajax Pagination and Infinite Scroll plugin <= 2.0.1 versions.

CVE
#csrf#vulnerability#wordpress#auth
CVE-2023-34177: WordPress WP-Cache.com plugin <= 1.1.1 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Kenth Hagström WP-Cache.Com plugin <= 1.1.1 versions.

CVE-2023-5540: Official Moodle git projects - moodle.git/search

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

CVE-2023-5541: Official Moodle git projects - moodle.git/search

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVE-2023-5547: Official Moodle git projects - moodle.git/search

The course upload preview contained an XSS risk for users uploading unsafe data.

CVE-2023-5539: Official Moodle git projects - moodle.git/search

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

CVE-2023-5550: Official Moodle git projects - moodle.git/search

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

CVE-2023-5551: Official Moodle git projects - moodle.git/search

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

CVE-2023-5545: Official Moodle git projects - moodle.git/search

H5P metadata automatically populated the author with the user's username, which could be sensitive information.