VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2019-10187MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

  • CVE-2019-3852MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

  • CVE-2019-3851MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

  • CVE-2019-3850MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header…

  • CVE-2018-10890MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

  • CVE-2018-10889MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

  • CVE-2018-1136MedMay 25, 2018
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move…

  • CVE-2018-1044MedJan 22, 2018
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

  • CVE-2017-12157MedSep 18, 2017
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

  • CVE-2017-7531MedJul 17, 2017
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.3, the course overview block reveals activities in hidden courses.

  • CVE-2016-3733MedApr 20, 2017
    risk 0.21cvss 4.3epss 0.01

    The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

  • CVE-2016-2159MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for…

  • CVE-2016-2158MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by…

  • CVE-2016-2156MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive…

  • CVE-2016-2155MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging…

  • CVE-2016-2154MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a…

  • CVE-2016-2151MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover…

  • CVE-2016-0724MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which…

  • CVE-2015-5342MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

  • CVE-2015-5341MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

Page 14 of 32