The version of Moodle installed on the remote host is 3.9.x prior to 3.9.13, 3.10.x prior to 3.10.10 or 3.11.x prior to 3.11.6. It is, therefore, affected by multiple vulnerabilities:
An SQL injection vulnerability in the badges code relating to configuring criteria available by default to teachers and managers. (CVE-2022-0983)
An authorization issue allowing users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. (CVE-2022-0985)
An authorization issue allowing users with the capability to configure badge criteria (teachers and managers by default) to configure course badges with profile field criteria, which should only be available for site badges. (CVE-2022-0984)
A vulnerable version of the PHPMailer library included in Moodle.
A vulnerable version of the CKEditor component included in the h5p-editor-php-library in Moodle.
Note that the scanner has not attempted to exploit this issue but has instead relied only on application’s self-reported version number.
No source data
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0983
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0984
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0985
moodle.org/mod/forum/discuss.php?d=432947#p1742073
moodle.org/mod/forum/discuss.php?d=432948#p1742074
moodle.org/mod/forum/discuss.php?d=432949#p1742075
moodle.org/mod/forum/discuss.php?d=432950#p1742077
moodle.org/mod/forum/discuss.php?d=432951#p1742078