Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2017-12156

Disclosure Date: September 18, 2017 (last updated November 26, 2024)
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
0
Attacker Value
Unknown

CVE-2017-12157

Disclosure Date: September 18, 2017 (last updated November 26, 2024)
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
0
Attacker Value
Unknown

CVE-2017-7532

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
In Moodle 3.x, course creators are able to change system default settings for courses.
0
Attacker Value
Unknown

CVE-2017-2642

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Moodle 3.x has user fullname disclosure on the user preferences page.
0
Attacker Value
Unknown

CVE-2013-7341

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
0