Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

  • EPSS 0.2%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified...

  • EPSS 0.3%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

  • EPSS 0.25%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a ...

  • EPSS 0.22%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging ...

  • EPSS 0.3%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsub...

  • EPSS 0.23%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

  • EPSS 0.44%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by ...

  • EPSS 0.35%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

  • EPSS 0.21%
  • Veröffentlicht 23.07.2012 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the i...