Moodle

Moodle

601 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 17.02.2020 16:15:28
  • Last modified 21.11.2024 05:11:10

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

  • EPSS 0.44%
  • Published 11.02.2020 14:15:17
  • Last modified 21.11.2024 04:32:50

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOT...

Exploit
  • EPSS 0.21%
  • Published 07.01.2020 17:15:11
  • Last modified 21.11.2024 04:27:35

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

  • EPSS 0.47%
  • Published 14.11.2019 17:15:13
  • Last modified 21.11.2024 01:36:35

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

  • EPSS 0.58%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

  • EPSS 0.95%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

  • EPSS 0.95%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2: Overview report allows users to see hidden courses

  • EPSS 0.75%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

  • EPSS 0.95%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

  • EPSS 0.99%
  • Published 14.11.2019 17:15:12
  • Last modified 21.11.2024 01:36:34

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.