Filtered by vendor Moodle
Subscriptions
Filtered by product Moodle
Subscriptions
Total
542 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2016-7919 | 1 Moodle | 1 Moodle | 2024-08-06 | 7.5 High |
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields. | ||||
CVE-2016-7038 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | ||||
CVE-2016-5014 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | ||||
CVE-2016-5012 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | ||||
CVE-2016-5013 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. | ||||
CVE-2016-3731 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions. | ||||
CVE-2016-3734 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read. | ||||
CVE-2016-3732 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. | ||||
CVE-2016-3733 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber. | ||||
CVE-2016-3729 | 1 Moodle | 1 Moodle | 2024-08-06 | N/A |
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator. | ||||
CVE-2016-2190 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log. | ||||
CVE-2016-2152 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field. | ||||
CVE-2016-2158 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request. | ||||
CVE-2016-2157 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins. | ||||
CVE-2016-2155 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role. | ||||
CVE-2016-2159 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request. | ||||
CVE-2016-2156 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request. | ||||
CVE-2016-2153 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field. | ||||
CVE-2016-2151 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list. | ||||
CVE-2016-2154 | 1 Moodle | 1 Moodle | 2024-08-05 | N/A |
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule. |