No coverage found in monitored research blogs or news feeds.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2024-43425 | 8.1 High | — A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi… |
| CVE-2024-43434 | 8.1 High | — The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil… |
| CVE-2024-43428 | 7.7 High | — To address a cache poisoning risk in Moodle, additional validation for local storage was required. |
| CVE-2024-43426 | 7.5 High | — A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is avail… |
| CVE-2024-43431 | 7.5 High | — A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access. |
| CVE-2024-43440 | 7.5 High | — A flaw was found in moodle. A local file may include risks when restoring block backups. |
| CVE-2024-43436 | 7.2 High | — A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. |
| CVE-2024-43439 | 5.4 Medium | — A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. |
Extracted from the publication text. Each CVE links to its tracked detail page.
No KEV-catalogued vendors are named in this publication.