Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 525 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-8643 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
CVE-2017-2576 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 5.3 MEDIUM
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
CVE-2016-2190 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 5.3 MEDIUM
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
CVE-2016-2159 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request.
CVE-2016-2156 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.
CVE-2016-0724 2 Fedoraproject, Moodle 2 Fedora, Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.
CVE-2016-7038 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 7.3 HIGH
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVE-2016-2151 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.
CVE-2016-3733 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
CVE-2016-2158 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.
CVE-2016-5013 1 Moodle 1 Moodle 2020-12-01 5.8 MEDIUM 5.4 MEDIUM
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
CVE-2016-3731 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 5.3 MEDIUM
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
CVE-2016-8642 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM 5.3 MEDIUM
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2016-5014 1 Moodle 1 Moodle 2020-12-01 5.8 MEDIUM 5.4 MEDIUM
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
CVE-2016-2152 1 Moodle 1 Moodle 2020-12-01 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.
CVE-2016-2154 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM 4.3 MEDIUM
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.
CVE-2016-2157 1 Moodle 1 Moodle 2020-12-01 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
CVE-2016-2153 1 Moodle 1 Moodle 2020-12-01 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.
CVE-2014-3546 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM N/A
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.
CVE-2014-9060 1 Moodle 1 Moodle 2020-12-01 5.0 MEDIUM N/A
The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.