
CVE-2023-1402 – Moodle: course participation report shows roles the user should not see
https://notcve.org/view.php?id=CVE-2023-1402
23 Mar 2023 — The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. • https://bugzilla.redhat.com/show_bug.cgi?id=2179427 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-668: Exposure of Resource to Wrong Sphere •

CVE-2021-36392
https://notcve.org/view.php?id=CVE-2021-36392
06 Mar 2023 — In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. • https://moodle.org/mod/forum/discuss.php?d=424797 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-36393 – Moodle 3.10.1 SQL Injection
https://notcve.org/view.php?id=CVE-2021-36393
06 Mar 2023 — In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. Moodle version 3.10.1 suffers from a remote time-based SQL injection vulnerability. • https://packetstorm.news/files/id/178051 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-36394
https://notcve.org/view.php?id=CVE-2021-36394
06 Mar 2023 — In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. • https://github.com/dinhbaouit/CVE-2021-36394 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-384: Session Fixation •

CVE-2021-36395
https://notcve.org/view.php?id=CVE-2021-36395
06 Mar 2023 — In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. • https://moodle.org/mod/forum/discuss.php?d=424801 • CWE-400: Uncontrolled Resource Consumption CWE-674: Uncontrolled Recursion •

CVE-2021-36396
https://notcve.org/view.php?id=CVE-2021-36396
06 Mar 2023 — In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. • https://github.com/T0X1Cx/CVE-2021-36396-Exploit • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2021-36397
https://notcve.org/view.php?id=CVE-2021-36397
06 Mar 2023 — In Moodle, insufficient capability checks meant message deletions were not limited to the current user. • https://moodle.org/mod/forum/discuss.php?d=424803 • CWE-276: Incorrect Default Permissions •

CVE-2021-36400
https://notcve.org/view.php?id=CVE-2021-36400
06 Mar 2023 — In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. • https://moodle.org/mod/forum/discuss.php?d=424806 • CWE-276: Incorrect Default Permissions CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2021-36401
https://notcve.org/view.php?id=CVE-2021-36401
06 Mar 2023 — In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. • https://moodle.org/mod/forum/discuss.php?d=424807 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-36402
https://notcve.org/view.php?id=CVE-2021-36402
06 Mar 2023 — In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. • https://moodle.org/mod/forum/discuss.php?d=424808 • CWE-20: Improper Input Validation •