Page 22 of 465 results (0.005 seconds)

CVSS: 8.8EPSS: 3%CPEs: 5EXPL: 2

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source. moodle en versiones anteriores a la 3.5.2, 3.4.5, 3.3.8 y 3.1.14 es vulnerable a una importación XML de ddwtos que podría conducir a la ejecución intencional de código de forma remota. Al importar preguntas heredadas de quiz de tipo "drag and drop into text" (ddwtos), era posible inyectar y ejecutar código PHP desde las preguntas importadas, ya sea de forma intencionada o importando preguntas de una fuente no fiable. Moodle versions 3.5.2, 3.4.5, 3.3.8, and 3.1.14 suffer from a remote php unserialize code execution vulnerability. • http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-62880 http://www.securityfocus.com/bid/105354 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14630 https://moodle.org/mod/forum/discuss.php?d=376023 https://seclists.org/fulldisclosure/2018/Sep/28 https://www.sec-consult.com/en/blog/advisories/remote-code-execution-php-unserialize-moodle-open-source-learning-platform-cve-2018-14630 • CWE-20: Improper Input Validation CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank. Se ha encontrado un error en Moodle en versiones anteriores a la 3.5.1, 3.4.4, 3.3.7 y la 3.1.13. Cuando se importa un banco de preguntas de test, era posible que la previsualización de preguntas mostrada ejecute JavaScript que se escribe en el banco de preguntas. • http://www.securityfocus.com/bid/104739 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10891 https://moodle.org/mod/forum/discuss.php?d=373371 • CWE-20: Improper Input Validation •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories. Se ha encontrado un error en Moodle en versiones anteriores a la 3.5.1, 3.4.4, 3.3.7 y la 3.1.13. Era posible que el servicio web core_course_get_categories devolviese categorías ocultas, lo que debería omitirse al recuperar categorías de curso. • http://www.securityfocus.com/bid/104738 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10890 https://moodle.org/mod/forum/discuss.php?d=373370 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. Se ha encontrado un error en Moodle en versiones anteriores a la 3.5.1, 3.4.4 y la 3.3.7. No existe una opción para omitir los registros de las exportaciones de privacidad de datos, lo que podría contener detalles de otros usuarios que interactuaban con el solicitante. • http://www.securityfocus.com/bid/104733 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10889 https://moodle.org/mod/forum/discuss.php?d=373369 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL. Se ha descubierto un problema en Moodle 3.x. Los estudiantes que publicaban en los foros y exportaban sus publicaciones a portfolios podían descargar cualquier archivo Moodle cambiando la URL de descarga. • http://www.securityfocus.com/bid/104307 https://moodle.org/mod/forum/discuss.php?d=371201 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •