Show filters
42 Total Results
Displaying 41-42 of 42
Sort by:
Attacker Value
Unknown
CVE-2015-3181
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.
0
Attacker Value
Unknown
CVE-2015-3175
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.
0