Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2016-5013
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
0
Attacker Value
Unknown
CVE-2017-2578
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 3.x, there is XSS in the assignment submission page.
0
Attacker Value
Unknown
CVE-2016-5012
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
0
Attacker Value
Unknown
CVE-2016-8642
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
0
Attacker Value
Unknown
CVE-2016-8643
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
0
Attacker Value
Unknown
CVE-2016-8644
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
0
Attacker Value
Unknown
CVE-2017-2576
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
0
Attacker Value
Unknown
CVE-2016-5014
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
0
Attacker Value
Unknown
CVE-2016-7038
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
0
Attacker Value
Unknown
CVE-2013-7341
Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
0