Skip to main content

Vendor archive

moodle CVEs

Beta · best-effort

631 CVEs tagged to vendor moodle23 Critical, 97 High, 463 Medium, 48 Low, 0 Unrated.

CVE-2011-4297

Published Jul 16, 2012

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4296

Published Jul 16, 2012

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4295

Published Jul 16, 2012

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4294

Published Jul 16, 2012

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL f…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4293

Published Jul 16, 2012

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4292

Published Jul 16, 2012

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4291

Published Jul 16, 2012

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4290

Published Jul 16, 2012

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors relat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4289

Published Jul 16, 2012

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtai…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4288

Published Jul 16, 2012

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz report…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4287

Published Jul 16, 2012

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by lev…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4286

Published Jul 16, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4285

Published Jul 16, 2012

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4284

Published Jul 16, 2012

Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4283

Published Jul 16, 2012

Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4282

Published Jul 16, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the course-tags functionality in tag/coursetags_more.php in Moodle 2.0.x before 2.0.2 allow remote attackers to inject arbit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4281

Published Jul 16, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that ma…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4279

Published Jul 16, 2012

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4278

Published Jul 16, 2012

Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4133

Published Jul 16, 2012

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4309

Published Jul 11, 2012

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4308

Published Jul 11, 2012

mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4307

Published Jul 11, 2012

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4306

Published Jul 11, 2012

Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via craf…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 631 CVEsPage 22 of 26