CVE-2016-3734
- EPSS 0.09%
- Published 20.04.2017 21:59:00
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks ...
CVE-2017-7298
- EPSS 0.24%
- Published 29.03.2017 05:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
CVE-2017-2641
- EPSS 1.9%
- Published 26.03.2017 18:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVE-2017-2643
- EPSS 0.76%
- Published 26.03.2017 18:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVE-2017-2644
- EPSS 0.29%
- Published 26.03.2017 18:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 3.x, XSS can occur via evidence of prior learning.
CVE-2017-2645
- EPSS 0.29%
- Published 26.03.2017 18:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVE-2016-5012
- EPSS 0.21%
- Published 20.01.2017 08:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
CVE-2016-5013
- EPSS 0.36%
- Published 20.01.2017 08:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
CVE-2016-5014
- EPSS 0.22%
- Published 20.01.2017 08:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
CVE-2016-7038
- EPSS 0.24%
- Published 20.01.2017 08:59:00
- Last modified 20.04.2025 01:37:25
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.