Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2017-2578

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 3.x, there is XSS in the assignment submission page.
0
Attacker Value
Unknown

CVE-2016-8642

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
0
Attacker Value
Unknown

CVE-2016-8643

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
0
Attacker Value
Unknown

CVE-2016-8644

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
0
Attacker Value
Unknown

CVE-2017-2576

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
0
Attacker Value
Unknown

CVE-2016-7038

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
0
Attacker Value
Unknown

CVE-2013-7341

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
0
Attacker Value
Unknown

CVE-2013-4939

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
0
Attacker Value
Unknown

CVE-2013-4940

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.
0
Attacker Value
Unknown

CVE-2013-4941

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
0