Loading HuntDB...

Version 3.11, 3.10 to 3.10.4, 3.9 to 3.9.7 and earlier unsupported versions

OTHER 10 CVEs

Known Vulnerabilities

CVE-2021-36400

In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

UNKNOWN CVSS 5.3 Published Mar 06, 2023

CVE-2021-36394

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

UNKNOWN Published Mar 06, 2023

CVE-2021-36403

In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

UNKNOWN CVSS 5.3 Published Mar 06, 2023

CVE-2021-36401

In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.

UNKNOWN CVSS 4.8 Published Mar 06, 2023

CVE-2021-36397

In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

UNKNOWN CVSS 5.3 Published Mar 06, 2023

CVE-2021-36393

In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

UNKNOWN Published Mar 06, 2023

CVE-2021-36402

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

UNKNOWN CVSS 5.3 Published Mar 06, 2023

CVE-2021-36396

In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.

UNKNOWN CVSS 7.5 Published Mar 06, 2023

CVE-2021-36392

In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

UNKNOWN Published Mar 06, 2023

CVE-2021-36395

In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

UNKNOWN CVSS 7.5 Published Mar 06, 2023