Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.0
CVE-2014-3552

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not chec…

Fix: after 2.3.11
Fix from $1,600 2014-07-29
Moodle MEDIUM 5.0
CVE-2014-3546

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requir…

Fix: after 2.3.11
Fix from $1,600 2014-07-29
Moodle HIGH 7.5
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remot…

Patch available
Fix from $1,950 2014-07-29
Moodle MEDIUM 6.8
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x bef…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Moodle MEDIUM 6.8
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token wi…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Moodle MEDIUM 5.0
CVE-2014-0216

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Moodle MEDIUM 6.8
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5…

Fix: after 2.3.11
Fix from $1,600 2014-03-24
Moodle MEDIUM 5.8
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, w…

Fix: after 2.3.11
Fix from $1,600 2014-03-24
Moodle MEDIUM 6.8
CVE-2014-0010

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.…

Patch available
Fix from $1,600 2014-01-20
Moodle MEDIUM 5.5
CVE-2014-0009

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the…

Fix: after 2.2.11
Fix from $1,600 2014-01-20
Moodle MEDIUM 6.8
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x befor…

Fix: after 2.2.11
Fix from $1,600 2013-11-26
Moodle MEDIUM 5.0
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP…

Fix: after 2.2.11
Fix from $1,600 2013-11-26
Moodle HIGH 7.5
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which…

Fix: after 2.2.11
Fix from $1,950 2013-09-16
Moodle HIGH 7.5
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, whi…

Patch available
Fix from $1,950 2013-09-16
Moodle MEDIUM 5.8
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verif…

Fix: after 2.2.11
Fix from $1,600 2013-09-16
Moodle MEDIUM 5.0
CVE-2013-2082

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comm…

Patch available
Fix from $1,600 2013-05-25
Moodle MEDIUM 5.0
CVE-2013-2083

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not prop…

Patch available
Fix from $1,600 2013-05-25
Moodle MEDIUM 6.5
CVE-2013-1836

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories…

Mitigation only
Fix from $1,600 2013-03-25
Moodle MEDIUM 5.0
CVE-2013-1831

lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive…

Patch available
Fix from $1,600 2013-03-25
Moodle MEDIUM 5.5
CVE-2012-6106

calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6104

blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6105

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed af…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6112

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.…

Patch available
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.8
CVE-2012-6103

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.4
CVE-2012-6102

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.8
CVE-2012-6101

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect us…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.5
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute…

Mitigation only
Fix from $1,600 2012-11-21
Moodle MEDIUM 6.4
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest…

Mitigation only
Fix from $1,600 2012-11-21
Moodle MEDIUM 6.5
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to acce…

Patch available
Fix from $1,600 2012-11-21
Moodle MEDIUM 5.5
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, …

Patch available
Fix from $1,600 2012-09-19