Skip to main content

Vendor archive

moodle CVEs

Beta · best-effort

631 CVEs tagged to vendor moodle23 Critical, 97 High, 463 Medium, 48 Low, 0 Unrated.

CVE-2011-4305

Published Jul 11, 2012

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4304

Published Jul 11, 2012

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4303

Published Jul 11, 2012

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4302

Published Jul 11, 2012

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4301

Published Jul 11, 2012

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConsta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4300

Published Jul 11, 2012

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4299

Published Jul 11, 2012

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4298

Published Jul 11, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authent…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4203

Published Dec 22, 2011

CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3757

Published Sep 23, 2011

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4208

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4207

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2231

Published Jun 28, 2010

Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2230

Published Jun 28, 2010

The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to c…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2229

Published Jun 28, 2010

Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2228

Published Jun 28, 2010

Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1619

Published Apr 29, 2010

Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1618

Published Apr 29, 2010

Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1617

Published Apr 29, 2010

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1616

Published Apr 29, 2010

Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capa…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1615

Published Apr 29, 2010

Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1614

Published Apr 29, 2010

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1613

Published Apr 29, 2010

Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4305

Published Dec 16, 2009

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4304

Published Dec 16, 2009

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 631 CVEsPage 23 of 26