Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown
CVE-2016-0725
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.
0
Attacker Value
Unknown
CVE-2015-5337
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
0
Attacker Value
Unknown
CVE-2015-5341
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5332
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
0