Medium
CVSS: 4.3
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finishe…
High
CVSS: 8.1
An SQL injection risk was identified in the module list filter within course search.
Low
CVSS: 3.1
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
Low
CVSS: 3.1
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
High
CVSS: 8.3
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
High
CVSS: 8.3
Description information displayed in the site administration live log
required additional sanitizing to prevent a stored XSS risk.
Low
CVSS: 3.4
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
Medium
CVSS: 5.3
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
Medium
CVSS: 6.5
Separate Groups mode restrictions were not factored into permission
checks before allowing viewing or deletion of responses in Feedback
activities.
High
CVSS: 8.6
Insufficient sanitizing in the TeX notation filter resulted in an
arbitrary file read risk on sites where pdfTeX is available (such as
those with TeX Live installed).