Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 607 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9060 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM N/A
The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.
CVE-2014-7833 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM N/A
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.
CVE-2016-8642 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 5.3 MEDIUM
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2015-2270 1 Moodle 1 Moodle 2020-12-01 4.3 MEDIUM N/A
lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain sensitive course information via unspecified vectors.
CVE-2014-7834 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM N/A
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.
CVE-2014-3553 1 Moodle 1 Moodle 2020-12-01 4.9 MEDIUM N/A
mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships.
CVE-2016-8643 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
CVE-2015-2267 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM N/A
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.
CVE-2015-5268 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
CVE-2014-7846 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM N/A
tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.
CVE-2014-3550 1 Moodle 1 Moodle 2020-12-01 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted (1) error or (2) success message for a scheduled task.
CVE-2014-3551 1 Moodle 1 Moodle 2020-12-01 3.5 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.
CVE-2016-2151 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.
CVE-2016-5013 1 Moodle 1 Moodle 2020-12-01 5.8 MEDIUM 5.4 MEDIUM
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
CVE-2014-3547 1 Moodle 1 Moodle 2020-12-01 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via an external badge.
CVE-2016-2155 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
CVE-2015-0213 1 Moodle 1 Moodle 2020-12-01 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.
CVE-2014-7845 1 Moodle 1 Moodle 2020-12-01 7.5 HIGH N/A
The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.
CVE-2014-7848 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM N/A
lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
CVE-2016-7038 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 7.3 HIGH
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.