Show filters
64 Total Results
Displaying 61-64 of 64
Sort by:
Attacker Value
Unknown

CVE-2014-0129

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-0123

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
0
Attacker Value
Unknown

CVE-2014-2571

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.
0
Attacker Value
Unknown

CVE-2014-0127

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.
0