Show filters
58 Total Results
Displaying 41-50 of 58
Sort by:
Attacker Value
Unknown
CVE-2015-5341
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5332
Disclosure Date: February 22, 2016 (last updated November 25, 2024)
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
0
Attacker Value
Unknown
CVE-2015-2271
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
0
Attacker Value
Unknown
CVE-2015-3174
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
0
Attacker Value
Unknown
CVE-2015-3180
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
0
Attacker Value
Unknown
CVE-2015-3179
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
0
Attacker Value
Unknown
CVE-2015-3177
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
0
Attacker Value
Unknown
CVE-2015-2266
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.
0
Attacker Value
Unknown
CVE-2015-3178
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
0
Attacker Value
Unknown
CVE-2015-2269
Disclosure Date: June 01, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.
0