Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 526 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12157 1 Moodle 1 Moodle 2017-09-28 4.0 MEDIUM 4.3 MEDIUM
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
CVE-2017-12156 1 Moodle 1 Moodle 2017-09-21 4.3 MEDIUM 6.1 MEDIUM
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
CVE-2017-2641 1 Moodle 1 Moodle 2017-08-16 7.5 HIGH 9.8 CRITICAL
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVE-2008-5153 1 Moodle 1 Moodle 2017-08-08 6.9 MEDIUM N/A
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
CVE-2006-4786 1 Moodle 1 Moodle 2017-07-20 5.0 MEDIUM N/A
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.
CVE-2006-4784 1 Moodle 1 Moodle 2017-07-20 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.
CVE-2017-2642 1 Moodle 1 Moodle 2017-07-19 4.0 MEDIUM 6.5 MEDIUM
Moodle 3.x has user fullname disclosure on the user preferences page.
CVE-2017-2645 1 Moodle 1 Moodle 2017-07-12 4.3 MEDIUM 6.1 MEDIUM
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVE-2017-2644 1 Moodle 1 Moodle 2017-07-12 4.3 MEDIUM 6.1 MEDIUM
In Moodle 3.x, XSS can occur via evidence of prior learning.
CVE-2017-2643 1 Moodle 1 Moodle 2017-07-12 5.0 MEDIUM 5.3 MEDIUM
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVE-2005-3648 1 Moodle 1 Moodle 2017-07-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.
CVE-2017-7491 1 Moodle 1 Moodle 2017-05-23 4.3 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVE-2017-2578 1 Moodle 1 Moodle 2017-01-25 4.3 MEDIUM 6.1 MEDIUM
In Moodle 3.x, there is XSS in the assignment submission page.
CVE-2016-5012 1 Moodle 1 Moodle 2017-01-25 5.0 MEDIUM 5.3 MEDIUM
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
CVE-2016-9186 1 Moodle 1 Moodle 2016-11-29 6.5 MEDIUM 8.8 HIGH
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2016-9188 1 Moodle 1 Moodle 2016-11-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
CVE-2016-9187 1 Moodle 1 Moodle 2016-11-29 6.5 MEDIUM 8.8 HIGH
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2005-3649 1 Moodle 1 Moodle 2016-10-18 2.6 LOW N/A
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.
CVE-2012-5472 1 Moodle 1 Moodle 2013-06-21 4.0 MEDIUM N/A
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
CVE-2011-3757 1 Moodle 1 Moodle 2012-03-12 5.0 MEDIUM N/A
Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.