Page 14 of 203 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 0

26 Jun 2019 — A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded. Se detecto un error en Moodle antes de la versión 3.7, 3.6.4, 3.5.6, 3.4.9 y 3.1.18. El tamaño de las cargas de archivos privados de los usuarios por correo electrónico no se comprobó correctamente, por lo que se podría superar su asignación de cuota. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

26 Jun 2019 — A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. Se detecto un error en Moodle antes de la versión 3.7, 3.6.4, 3.5.6, 3.4.9 y 3.1.18. El formulario para cargar cohorts contenía un campo de redirección, que no estaba restringido a las direcciones URL internas. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10133 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 5.4EPSS: 1%CPEs: 4EXPL: 1

27 Mar 2019 — A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf. Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5, 3.4.8 y 3.1.17. Los usuarios con la característica "login as other us... • https://github.com/danielthatcher/moodle-login-csrf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

26 Mar 2019 — A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities Se ha descubierto una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3. Las funciones get_with_capability_join y get_users_by_capability no tenían en cuenta el bloqueo de contexto al comprobar las capacidades del usuario. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3852 •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

26 Mar 2019 — A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. Se ha descubierto una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3 y la 3.5.5. Había un enlace al inicio del sitio en la capa segura del tema de Boost, lo que significa que los estudiantes podrían navegar fuera de la página. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3851 •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

26 Mar 2019 — A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits. Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5, 3.4.8 y 3.1.17. Los enlaces con comentarios de envío de tareas se abrirían directamente (en la misma... • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3850 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

26 Mar 2019 — A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5 y 3.4.8. Los usuarios podrían autoasignarse un rol escalado en los cursos o el contenido al que se accede mediante LTI modificando la petición al sitio LTI del editor. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 • CWE-269: Improper Privilege Management CWE-285: Improper Authorization •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

26 Mar 2019 — A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.) Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5 y 3.4.8. Los permisos no se comprobaban correctamente antes de cargar información de eventos en ... • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3848 • CWE-863: Incorrect Authorization •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

25 Mar 2019 — A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page. Se ha encontrado un error en Moodle, en versiones 3.1 a 3.1.15 y versiones anteriores sin soporte. La funcionalidad ‘‘mybackpack’’ ha permitido establecer la URL de las insignias cuando debería estar restringida la U... • http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222 • CWE-352: Cross-Site Request Forgery (CSRF) CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 5.4EPSS: 0%CPEs: 5EXPL: 0

25 Mar 2019 — A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default. Se ha encontrado un error en Moodle, en versiones 3.4 a 3.6.1, 3.3 a 3.5.3, 3.2 a 3.4.6 y 3.1 a 3.1.15, así como en versiones anteriores sin... • http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •