Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

  • EPSS 0.16%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a...

  • EPSS 0.14%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

  • EPSS 0.14%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

  • EPSS 0.28%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffi...

  • EPSS 0.17%
  • Veröffentlicht 21.07.2012 03:38:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already ...

  • EPSS 0.25%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

  • EPSS 0.44%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID number...

  • EPSS 0.14%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access ...

  • EPSS 0.36%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML...