Show filters
94 Total Results
Displaying 61-70 of 94
Sort by:
Attacker Value
Unknown
CVE-2012-4408
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
0
Attacker Value
Unknown
CVE-2012-3397
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
0
Attacker Value
Unknown
CVE-2012-3395
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
0
Attacker Value
Unknown
CVE-2012-3396
Disclosure Date: July 23, 2012 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
0
Attacker Value
Unknown
CVE-2012-3393
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.
0
Attacker Value
Unknown
CVE-2012-3392
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.
0
Attacker Value
Unknown
CVE-2012-3389
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.
0
Attacker Value
Unknown
CVE-2012-3398
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.
0
Attacker Value
Unknown
CVE-2012-3391
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.
0
Attacker Value
Unknown
CVE-2012-3394
Disclosure Date: July 23, 2012 (last updated October 04, 2023)
auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.
0