CVE-2016-9186
- EPSS 3.28%
- Veröffentlicht 04.11.2016 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via uns...
CVE-2016-7919
- EPSS 0.18%
- Veröffentlicht 28.10.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevan...
CVE-2016-2190
- EPSS 0.44%
- Veröffentlicht 22.05.2016 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
CVE-2016-2159
- EPSS 0.21%
- Veröffentlicht 22.05.2016 20:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by le...
CVE-2016-2158
- EPSS 0.33%
- Veröffentlicht 22.05.2016 20:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information ...
CVE-2016-2157
- EPSS 0.1%
- Veröffentlicht 22.05.2016 20:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication o...
CVE-2016-2156
- EPSS 0.3%
- Veröffentlicht 22.05.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated ...
CVE-2016-2155
- EPSS 0.3%
- Veröffentlicht 22.05.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude gra...
CVE-2016-2154
- EPSS 0.33%
- Veröffentlicht 22.05.2016 20:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course ...
CVE-2016-2153
- EPSS 0.22%
- Veröffentlicht 22.05.2016 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script ...