CVE-2012-1155
- EPSS 1.27%
- Published 14.11.2019 16:15:14
- Last modified 21.11.2024 01:36:33
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2012-1156
- EPSS 1.23%
- Published 14.11.2019 16:15:14
- Last modified 21.11.2024 01:36:33
Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1168
- EPSS 2.22%
- Published 14.11.2019 16:15:14
- Last modified 21.11.2024 01:36:34
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2019-10186
- EPSS 0.31%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
CVE-2019-10187
- EPSS 0.17%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
CVE-2019-10188
- EPSS 0.17%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
CVE-2019-10189
- EPSS 0.17%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
CVE-2019-10133
- EPSS 0.15%
- Published 26.06.2019 19:15:11
- Last modified 21.11.2024 04:18:29
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
CVE-2019-10134
- EPSS 0.18%
- Published 26.06.2019 19:15:11
- Last modified 21.11.2024 04:18:29
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
CVE-2019-10154
- EPSS 0.24%
- Published 26.06.2019 19:15:11
- Last modified 21.11.2024 04:18:31
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.