Show filters
94 Total Results
Displaying 51-60 of 94
Sort by:
Attacker Value
Unknown
CVE-2012-6098
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.
0
Attacker Value
Unknown
CVE-2012-6105
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
0
Attacker Value
Unknown
CVE-2012-5473
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
0
Attacker Value
Unknown
CVE-2012-5480
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.
0
Attacker Value
Unknown
CVE-2012-5479
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
0
Attacker Value
Unknown
CVE-2012-5471
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.
0
Attacker Value
Unknown
CVE-2012-4400
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
0
Attacker Value
Unknown
CVE-2012-4401
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
0
Attacker Value
Unknown
CVE-2012-4402
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
0
Attacker Value
Unknown
CVE-2012-4407
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
0