Search CVE reports
13131 – 13140 of 44632 results
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
1 affected package
hoteldruid
Package | 16.04 LTS |
---|---|
hoteldruid | Needs evaluation |
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to...
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
The course upload preview contained an XSS risk for users uploading unsafe data.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
1 affected package
moodle
Package | 16.04 LTS |
---|---|
moodle | Needs evaluation |