Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 22.02.2016 05:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhid...

  • EPSS 0.18%
  • Veröffentlicht 22.02.2016 05:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

  • EPSS 0.15%
  • Veröffentlicht 22.02.2016 05:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified ...

  • EPSS 0.17%
  • Veröffentlicht 22.02.2016 05:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1...

  • EPSS 0.16%
  • Veröffentlicht 22.02.2016 05:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenti...

  • EPSS 0.12%
  • Veröffentlicht 22.02.2016 05:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for reque...

  • EPSS 0.27%
  • Veröffentlicht 22.02.2016 05:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

  • EPSS 0.19%
  • Veröffentlicht 22.02.2016 05:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging t...

  • EPSS 0.07%
  • Veröffentlicht 22.02.2016 05:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for re...

  • EPSS 0.57%
  • Veröffentlicht 22.02.2016 05:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.