moodle vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the moodle package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

*
  • M
Arbitrary Code Injection

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
Arbitrary Code Injection

*
  • M
Open Redirect

*
  • M
Improper Input Validation

*
  • M
Cross-site Request Forgery (CSRF)

*
  • M
Missing Authorization

*
  • M
CVE-2019-10189

*
  • M
CVE-2019-10188

*
  • M
Improper Input Validation

*
  • M
Open Redirect

*
  • M
CVE-2019-3852

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Improper Privilege Management

*
  • M
Exposure of Resource to Wrong Sphere

*
  • L
Cross-site Request Forgery (CSRF)

*
  • M
Improper Privilege Management

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • M
Improper Access Control

*
  • M
Access Restriction Bypass

*
  • M
Improper Access Control

*
  • M
Arbitrary Code Injection

*
  • L
Information Exposure

*
  • L
Weak Password Recovery Mechanism for Forgotten Password

*
  • L
Cross-site Scripting (XSS)

*
  • L
Improper Input Validation

*
  • L
Cross-site Request Forgery (CSRF)

<3.0.3+dfsg-0ubuntu1
  • L
Information Exposure

<3.0.3+dfsg-0ubuntu1
  • L
Information Exposure

<3.0.3+dfsg-0ubuntu1
  • L
Access Restriction Bypass

<3.0.3+dfsg-0ubuntu1
  • L
Information Exposure

<3.0.3+dfsg-0ubuntu1
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Arbitrary Code Injection

*
  • M
Improper Input Validation

*
  • L
Access Restriction Bypass

*
  • M
Access Restriction Bypass

*
  • L
Access Restriction Bypass

*
  • M
Access Restriction Bypass

*
  • L
Information Exposure

*
  • M
Information Exposure

*
  • L
Information Exposure

*
  • M
Cross-site Scripting (XSS)

*
  • M
Access Restriction Bypass

*
  • M
Access Restriction Bypass

*
  • M
Arbitrary Code Injection

*
  • L
Information Exposure

*