CVE-2016-5013
- EPSS 0.36%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
CVE-2016-5014
- EPSS 0.22%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
CVE-2016-7038
- EPSS 0.24%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVE-2016-8642
- EPSS 0.22%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2016-8643
- EPSS 0.19%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
CVE-2016-8644
- EPSS 0.28%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
CVE-2017-2576
- EPSS 0.29%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
CVE-2017-2578
- EPSS 0.26%
- Veröffentlicht 20.01.2017 08:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Moodle 3.x, there is XSS in the assignment submission page.
CVE-2016-9188
- EPSS 0.37%
- Veröffentlicht 04.11.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
CVE-2016-9187
- EPSS 3.28%
- Veröffentlicht 04.11.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspe...