Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-5cvx-cwpx-9rjh: Moodle Code Injection vulnerability

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

ghsa
#vulnerability#web#git#rce
GHSA-jr83-8x65-xcr5: Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

GHSA-26fg-v32r-h663: Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

GHSA-cwh2-q44x-5w3c: Moodle Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

GHSA-j5xf-gv89-g422: Moodle Cross-site Scripting vulnerability

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

GHSA-fm5h-58g2-4m3f: Moodle Improper Access Control vulnerability

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

GHSA-w8x2-w4qr-v3x4: Moodle Code Injection vulnerability

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

GHSA-28gc-4qq5-8q26: Moodle Cross-site Scripting vulnerability

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

GHSA-3xxm-3g3c-w579: Moodle Code Injection vulnerability

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

GHSA-9724-h8p7-r3jv: Moodle Cross-site Scripting vulnerability

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.