Show filters
552 Total Results
Displaying 171-180 of 552
Sort by:
Attacker Value
Unknown
CVE-2012-1155
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
0
Attacker Value
Unknown
CVE-2012-1156
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2 has users' private files included in course backups
0
Attacker Value
Unknown
CVE-2019-10187
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
0
Attacker Value
Unknown
CVE-2019-10188
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
0
Attacker Value
Unknown
CVE-2019-10186
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
0
Attacker Value
Unknown
CVE-2019-10154
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
0
Attacker Value
Unknown
CVE-2019-10133
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
0
Attacker Value
Unknown
CVE-2019-10134
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
0
Attacker Value
Unknown
CVE-2019-3847
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
0
Attacker Value
Unknown
CVE-2019-3848
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
0