CVE-2020–25627, CVE-2020–14321, CVE-2020–25629, CVE-2019-11631
Do we really need to introduce what Moodle is....? 😅CVE-2019-11631
A vulnerability classified as critical was found in Moodle 3.6.3 . This vulnerability affects a code block of the file repository/repository_ajax.php?action=upload of the component ZIP File Handler.CVE-2020–14321
CVE-2020-14321 is a privilege escalation vulnerability impacting multiple versions of Moodle. The vulnerability is found In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, and it could be exploited if you either have teacher credentials (don't know how likely that is) or a teacher cookie, as demonstrated in the video.CVE-2020-25629
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager.CVE-2020-25627
Stored cross-site scripting (also known as second-order or persistent XSS) when an attacker is able to inject malicious code into the website or application, which is then stored in a database or other data store.