Skip to main content

Vendor archive

moodle CVEs

Beta · best-effort

631 CVEs tagged to vendor moodle23 Critical, 97 High, 463 Medium, 48 Low, 0 Unrated.

CVE-2009-4303

Published Dec 16, 2009

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4302

Published Dec 16, 2009

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause l…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4301

Published Dec 16, 2009

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to ex…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4300

Published Dec 16, 2009

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4299

Published Dec 16, 2009

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauth…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4298

Published Dec 16, 2009

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4297

Published Dec 16, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified vict…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1171

Published Mar 30, 2009

The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6125

Published Feb 13, 2009

Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to gain privileges via unknown ve…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6124

Published Feb 13, 2009

SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0502

Published Feb 10, 2009

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0501

Published Feb 10, 2009

Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0500

Published Feb 10, 2009

Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0499

Published Feb 10, 2009

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5432

Published Dec 11, 2008

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5153

Published Nov 18, 2008

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3325

Published Jul 25, 2008

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3326

Published Jul 25, 2008

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3327

Published Jul 25, 2008

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/rep…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1502

Published Mar 25, 2008

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0123

Published Jan 12, 2008

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6538

Published Dec 27, 2007

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3555

Published Jul 4, 2007

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1647

Published Mar 24, 2007

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1429

Published Mar 13, 2007

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.ph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 631 CVEsPage 24 of 26