Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown
CVE-2016-2190
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
0
Attacker Value
Unknown
CVE-2016-2155
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
0
Attacker Value
Unknown
CVE-2015-5335
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.
0
Attacker Value
Unknown
CVE-2015-5331
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
0
Attacker Value
Unknown
CVE-2015-5336
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
0
Attacker Value
Unknown
CVE-2015-5342
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.
0
Attacker Value
Unknown
CVE-2015-5338
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1) mod/lesson/mediafile.php or (2) mod/lesson/view.php.
0
Attacker Value
Unknown
CVE-2015-5339
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.
0
Attacker Value
Unknown
CVE-2016-0724
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.
0
Attacker Value
Unknown
CVE-2015-5340
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.
0