Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2011-4287 admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote att… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.5 CVE-2011-4285 The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authentic… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4279 Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attacke… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4283 Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to … Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4284 Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context … Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4309 Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by levera… Moodle Mitigation only Fix from $1,6002012-07-11 MEDIUM 6.8 CVE-2011-4298 Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote a… Moodle Patch available Fix from $1,6002012-07-11 MEDIUM 6.8 CVE-2011-4302 mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value o… Moodle Patch available Fix from $1,6002012-07-11 MEDIUM 5.0 CVE-2011-4300 The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which a… Moodle Patch available Fix from $1,6002012-07-11 MEDIUM 5.0 CVE-2011-4301 The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not… Moodle Mitigation only Fix from $1,6002012-07-11 MEDIUM 5.0 CVE-2011-4203 CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and… Moodle No fix yet Fix from $1,6002011-12-22 MEDIUM 5.0 CVE-2011-3757 Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e… Moodle No fix yet Fix from $1,6002011-09-23 MEDIUM 6.8 CVE-2010-2231 Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow… Moodle after 1.8.12 Fix from $1,6002010-06-28 HIGH 7.5 CVE-2010-1615 Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands … Moodle Mitigation only Fix from $1,9502010-04-29 MEDIUM 6.8 CVE-2010-1613 Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote att… Moodle Mitigation only Fix from $1,6002010-04-29 HIGH 7.5 CVE-2009-4304 Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute… Moodle Patch available Fix from $1,9502009-12-16 MEDIUM 6.8 CVE-2009-4297 Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the auth… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 6.5 CVE-2009-4305 SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitra… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 6.0 CVE-2009-4301 mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remo… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4298 The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within t… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4299 mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which a… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4300 Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, ev… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4302 login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an H… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4303 Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers t… Moodle Patch available Fix from $1,6002009-12-16 HIGH 7.5 CVE-2008-6124 SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before… Moodle 1.6.7 / 1.7.5+ Fix from $1,9502009-02-13 MEDIUM 6.5 CVE-2008-6125 Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to … Moodle 1.6.6 / 1.7.3+ Fix from $1,6002009-02-13 MEDIUM 6.4 CVE-2009-0499 Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote at… Moodle Mitigation only Fix from $1,6002009-02-10 MEDIUM 5.0 CVE-2009-0501 Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive informa… Moodle No fix yet Fix from $1,6002009-02-10 MEDIUM 6.9 CVE-2008-5153 spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2)… Moodle No fix yet Fix from $1,6002008-11-18 MEDIUM 6.0 CVE-2008-3325 Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile setting… Moodle 1.6.7 / 1.7.5+ Fix from $1,6002008-07-25