Show filters
88 Total Results
Displaying 31-40 of 88
Sort by:
Attacker Value
Unknown

CVE-2012-3397

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
0
Attacker Value
Unknown

CVE-2012-3395

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
0
Attacker Value
Unknown

CVE-2012-3396

Disclosure Date: July 23, 2012 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
0
Attacker Value
Unknown

CVE-2012-3398

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.
0
Attacker Value
Unknown

CVE-2012-2364

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.
0
Attacker Value
Unknown

CVE-2012-2361

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
0
Attacker Value
Unknown

CVE-2012-2360

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.
0
Attacker Value
Unknown

CVE-2012-2365

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.
0
Attacker Value
Unknown

CVE-2012-2367

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.
0
Attacker Value
Unknown

CVE-2012-2358

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
0