Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2016-5013

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
0
Attacker Value
Unknown

CVE-2017-2578

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 3.x, there is XSS in the assignment submission page.
0
Attacker Value
Unknown

CVE-2016-5012

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
0
Attacker Value
Unknown

CVE-2016-8642

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
0
Attacker Value
Unknown

CVE-2016-8643

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
0
Attacker Value
Unknown

CVE-2016-8644

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
0
Attacker Value
Unknown

CVE-2017-2576

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
0
Attacker Value
Unknown

CVE-2016-5014

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
0
Attacker Value
Unknown

CVE-2016-7038

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
0
Attacker Value
Unknown

CVE-2013-7341

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
0