Search

Found 290 results in 32ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-7834 medium 4.0 moodle 12y ago Moodle does not verify group permissions
CVE-2014-7833 medium 4.0 moodle 12y ago Moodle allows attackers to obtain sensitive information
CVE-2014-7832 medium 4.0 moodle 12y ago Moodle allows attackers to bypass the mod/lti:view capability requirement
CVE-2014-7831 medium 4.0 moodle 12y ago Moodle exposes hidden grades to students
CVE-2014-7830 low 3.5 moodle 12y ago Moodle cross-site scripting (XSS) vulnerability
CVE-2014-3617 medium 4.0 moodle 12y ago Moodle allows discovery of an author's username
CVE-2014-3553 medium 4.9 moodle 12y ago Moodle does not enforce the moodle/site:accessallgroups capability requirement
CVE-2014-3552 medium 6.0 moodle 12y ago The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remo…
CVE-2014-3551 low 3.5 moodle 12y ago Moodle multiple cross-site scripting (XSS) vulnerabilities
CVE-2014-3550 medium 4.3 moodle 12y ago Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that t…
CVE-2014-3549 medium 4.3 moodle 12y ago Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script…
CVE-2014-3548 medium 4.3 moodle 12y ago Moodle multiple cross-site scripting (XSS) vulnerabilities
CVE-2014-3547 medium 4.3 moodle 12y ago Moodle multiple cross-site scripting (XSS) vulnerabilities
CVE-2014-3546 medium 5.0 moodle 12y ago Moodle allows attackers to obtain username and course information
CVE-2014-3545 medium 6.0 moodle 12y ago Moodle remote code execution via quiz questions
CVE-2014-3544 low 4.5 EXP moodle 12y ago Moodle cross-site scripting (XSS) vulnerability
CVE-2014-3543 medium 4.3 moodle 12y ago Moodle Arbitrary File Read via XML External Entity vulnerability
CVE-2014-3542 medium 4.3 moodle 12y ago Moodle allows remote attackers to read arbitrary files
CVE-2014-3541 high 7.5 moodle 12y ago Moodle vulnerable to PHP object injection attacks
CVE-2014-0218 medium 4.3 moodle 12y ago Moodle cross-site scripting (XSS) vulnerability
CVE-2014-0217 medium 4.3 moodle 12y ago Moodle does not check for the moodle/course:viewhiddencourses capability
CVE-2014-0216 medium 5.0 moodle 12y ago Moodle does not properly restrict file access
CVE-2014-0215 medium 4.0 moodle 12y ago Moodle Reveals Student Information Meant To Be Anonymous
CVE-2014-0214 medium 6.8 moodle 12y ago Moodle creates a MoodleMobile web-service token with an infinite lifetime
CVE-2014-0213 medium 6.8 moodle 12y ago Moodle multiple cross-site request forgery (CSRF) vulnerabilities
CVE-2014-2572 medium 4.0 moodle 12y ago Moodle attackers to modify grade metadata
CVE-2014-2571 low 3.5 moodle 12y ago Moodle cross-site scripting (XSS) vulnerability
CVE-2014-0129 medium 4.0 moodle 12y ago Moodle allows attackers to modify the visibility of a badge
CVE-2014-0127 medium 4.9 moodle 12y ago Moodle's time-validation implementation allows bypassing intended restrictions
CVE-2014-0126 medium 6.8 moodle 12y ago Moodle cross-site request forgery (CSRF) vulnerability
CVE-2014-0125 medium 5.8 moodle 12y ago Moodle places a session key in a URL
CVE-2014-0124 medium 4.0 moodle 12y ago Moodle allows attackers to obtain sensitive information
CVE-2014-0123 medium 4.9 moodle 12y ago Moodle does not properly restrict access
CVE-2014-0122 medium 4.9 moodle 12y ago Moodle allows bypass of intended access restrictions
CVE-2013-7341 medium 4.3 flowplayermoodle 12y ago Moodle cross-site scripting (XSS) vulnerabilities
CVE-2014-0010 medium 6.8 fedora fedora moodle 13y ago Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allo…
CVE-2014-0009 medium 5.5 moodle 13y ago course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requiremen…
CVE-2014-0008 medium 4.0 moodle 13y ago lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitiv…
CVE-2013-4525 low 3.5 moodle 13y ago Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authe…
CVE-2013-4524 medium 6.8 moodle 13y ago Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read …
CVE-2013-4523 low 3.5 moodle 13y ago Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbit…
CVE-2013-4522 medium 5.0 moodle 13y ago Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2013-3630 medium 5.6 EXP moodle 13y ago Moodle Authenticated Spelling Binary Remote Code Execution
CVE-2013-5674 high 7.5 moodle 13y ago badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object i…
CVE-2013-4341 medium 5.3 EXP moodle 13y ago Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or H…
CVE-2013-4313 high 7.5 moodle 13y ago Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injec…
CVE-2012-6087 medium 5.8 moodle 13y ago repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name i…
CVE-2013-4942 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4941 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4940 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4939 medium 4.3 moodleyahoo 13y ago Cross-Site Scripting in yui
CVE-2013-4938 medium 4.3 moodle 13y ago The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sen…
CVE-2013-2246 medium 4.0 moodle 13y ago mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying…
CVE-2013-2245 medium 4.0 moodle 13y ago rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which a…
CVE-2013-2244 medium 4.3 moodle 13y ago Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the c…
CVE-2013-2243 medium 4.0 moodle 13y ago mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by …
CVE-2013-2242 medium 4.0 moodle 13y ago mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before auth…
CVE-2013-2083 medium 5.0 moodle 13y ago Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
CVE-2013-2082 medium 5.0 moodle 13y ago Moodle does not enforce capability requirements for reading blog comments
CVE-2013-2081 medium 4.3 moodle 13y ago Moodle does not consider "don't send" attributes during hub registration
CVE-2013-2080 medium 4.0 moodle 13y ago Moodle is vulnerable to Sensitive Information Disclosure
CVE-2013-2079 medium 4.0 moodle 13y ago mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download…
CVE-2013-1836 medium 6.5 moodle 13y ago Moodle does not properly manage privileges for WebDAV repositories
CVE-2013-1835 low 3.5 moodle 13y ago Moodle's login_as feature leaks information from external repositories
CVE-2013-1834 medium 4.0 moodle 13y ago Moodle allows remote authenticated users to reassign notes
CVE-2013-1833 low 3.5 moodle 13y ago Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module
CVE-2013-1832 medium 4.0 moodle 13y ago Moodle includes the WebDAV password in the configuration form
CVE-2013-1831 medium 5.0 moodle 13y ago Moodle reveals absolute path in exception message
CVE-2013-1830 medium 5.0 fedora fedora moodle 13y ago Moodle does not enforce the forceloginforprofiles setting
CVE-2013-1829 medium 4.0 moodle 13y ago calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain pot…
CVE-2012-6112 medium 5.0 FIX debian debian tinymcemoodle 14y ago classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x be…
CVE-2012-6106 medium 5.5 moodle 14y ago calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calen…
CVE-2012-6105 medium 5.0 moodle 14y ago blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote atta…
CVE-2012-6104 medium 5.0 moodle 14y ago blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and…
CVE-2012-6103 medium 6.8 moodle 14y ago Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote atta…
CVE-2012-6102 medium 6.4 moodle 14y ago lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback …
CVE-2012-6101 medium 5.8 moodle 14y ago Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing at…
CVE-2012-6100 medium 4.0 moodle 14y ago report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remo…
CVE-2012-6099 medium 4.0 moodle 14y ago Moodle Arbitrary File Read via Backup Functionality
CVE-2012-6098 medium 4.0 moodle 14y ago grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage …
CVE-2012-5481 medium 4.0 moodle 14y ago Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
CVE-2012-5480 medium 6.4 moodle 14y ago The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries vi…
CVE-2012-5479 medium 6.5 moodle 14y ago The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
CVE-2012-5473 medium 4.0 moodle 14y ago The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an ad…
CVE-2012-5472 medium 4.0 moodle 14y ago lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
CVE-2012-5471 medium 6.5 moodle 14y ago Moodle Allows Unauthenticated Dropbox Access
CVE-2012-4408 medium 5.5 moodle 14y ago course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass …
CVE-2012-4407 medium 5.0 moodle 14y ago lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive…
CVE-2012-4403 medium 5.0 moodle 14y ago theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a r…
CVE-2012-4402 medium 4.9 moodle 14y ago webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run ar…
CVE-2012-4401 medium 4.0 moodle 14y ago Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabiliti…
CVE-2012-4400 medium 4.0 moodle 14y ago repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
CVE-2012-3398 medium 4.0 moodle 14y ago Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU…
CVE-2012-3397 medium 4.0 moodle 14y ago lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity…
CVE-2012-3396 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrato…
CVE-2012-3395 medium 6.5 moodle 14y ago SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands …
CVE-2012-3394 medium 5.0 moodle 14y ago auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows r…
CVE-2012-3393 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by…
CVE-2012-3392 medium 5.5 moodle 14y ago mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription re…
CVE-2012-3391 medium 4.0 moodle 14y ago mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to…