Show filters
74 Total Results
Displaying 71-74 of 74
Sort by:
Attacker Value
Unknown

CVE-2012-2358

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
0
Attacker Value
Unknown

CVE-2012-2353

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
0
Attacker Value
Unknown

CVE-2012-2359

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
0
Attacker Value
Unknown

CVE-2012-2366

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
0