Show filters
67 Total Results
Displaying 41-50 of 67
Sort by:
Attacker Value
Unknown
CVE-2015-5341
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5332
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
0
Attacker Value
Unknown
CVE-2015-0214
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.
0
Attacker Value
Unknown
CVE-2015-2271
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
0
Attacker Value
Unknown
CVE-2015-0211
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
0
Attacker Value
Unknown
CVE-2015-0215
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.
0
Attacker Value
Unknown
CVE-2015-3174
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
0
Attacker Value
Unknown
CVE-2015-3180
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
0
Attacker Value
Unknown
CVE-2015-3179
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
0
Attacker Value
Unknown
CVE-2015-0216
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.
0