VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2012-0792Jul 17, 2012
    risk 0.00cvss —epss 0.01

    mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

  • CVE-2011-4297Jul 16, 2012
    risk 0.00cvss —epss 0.02

    comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

  • CVE-2011-4296Jul 16, 2012
    risk 0.00cvss —epss 0.01

    lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

  • CVE-2011-4295Jul 16, 2012
    risk 0.00cvss —epss 0.01

    The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

  • CVE-2011-4294Jul 16, 2012
    risk 0.00cvss —epss 0.02

    The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web…

  • CVE-2011-4293Jul 16, 2012
    risk 0.00cvss —epss 0.02

    The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary…

  • CVE-2011-4292Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.

  • CVE-2011-4291Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

  • CVE-2011-4290Jul 16, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

  • CVE-2011-4289Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

  • CVE-2011-4288Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

  • CVE-2011-4287Jul 16, 2012
    risk 0.00cvss —epss 0.02

    admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

  • CVE-2011-4286Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka…

  • CVE-2011-4285Jul 16, 2012
    risk 0.00cvss —epss 0.02

    The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.

  • CVE-2011-4284Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.

  • CVE-2011-4283Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.

  • CVE-2011-4282Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the course-tags functionality in tag/coursetags_more.php in Moodle 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sort or (2) show parameter.

  • CVE-2011-4281Jul 16, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.

  • CVE-2011-4280Jul 16, 2012
    risk 0.00cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-4279Jul 16, 2012
    risk 0.00cvss —epss 0.01

    Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search…

  • CVE-2011-4278Jul 16, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-4133Jul 16, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.

  • CVE-2011-4309Jul 11, 2012
    risk 0.00cvss —epss 0.01

    Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

  • CVE-2011-4308Jul 11, 2012
    risk 0.00cvss —epss 0.02

    mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

  • CVE-2011-4307Jul 11, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

  • CVE-2011-4306Jul 11, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.

  • CVE-2011-4305Jul 11, 2012
    risk 0.00cvss —epss 0.02

    message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

  • CVE-2011-4304Jul 11, 2012
    risk 0.00cvss —epss 0.02

    The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

  • CVE-2011-4303Jul 11, 2012
    risk 0.00cvss —epss 0.01

    lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

  • CVE-2011-4302Jul 11, 2012
    risk 0.00cvss —epss 0.01

    mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

  • CVE-2011-4301Jul 11, 2012
    risk 0.00cvss —epss 0.02

    The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the…

  • CVE-2011-4300Jul 11, 2012
    risk 0.00cvss —epss 0.02

    The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

  • CVE-2011-4299Jul 11, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

  • CVE-2011-4298Jul 11, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

  • CVE-2011-4203Dec 22, 2011
    risk 0.00cvss —epss 0.01

    CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving…

  • CVE-2011-3757Sep 23, 2011
    risk 0.00cvss —epss 0.01

    Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

  • CVE-2010-2231Jun 28, 2010
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid…

  • CVE-2010-2230Jun 28, 2010
    risk 0.00cvss —epss 0.02

    The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

  • CVE-2010-2229Jun 28, 2010
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2010-2228Jun 28, 2010
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.

  • CVE-2010-1619Apr 29, 2010
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML…

  • CVE-2010-1618Apr 29, 2010
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.

  • CVE-2010-1617Apr 29, 2010
    risk 0.00cvss —epss 0.02

    user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

  • CVE-2010-1616Apr 29, 2010
    risk 0.00cvss —epss 0.01

    Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.

  • CVE-2010-1615Apr 29, 2010
    risk 0.00cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms…

  • CVE-2010-1614Apr 29, 2010
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified…

  • CVE-2010-1613Apr 29, 2010
    risk 0.00cvss —epss 0.02

    Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.

  • CVE-2009-4305Dec 16, 2009
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

  • CVE-2009-4304Dec 16, 2009
    risk 0.00cvss —epss 0.02

    Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

  • CVE-2009-4303Dec 16, 2009
    risk 0.00cvss —epss 0.02

    Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

Page 12 of 13