CVE-2015-5336
- EPSS 0.19%
- Veröffentlicht 22.02.2016 05:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging t...
CVE-2015-5335
- EPSS 0.07%
- Veröffentlicht 22.02.2016 05:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for re...
CVE-2015-5332
- EPSS 0.57%
- Veröffentlicht 22.02.2016 05:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
CVE-2015-5331
- EPSS 0.18%
- Veröffentlicht 22.02.2016 05:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
CVE-2015-5272
- EPSS 0.26%
- Veröffentlicht 22.02.2016 05:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
CVE-2015-5269
- EPSS 0.19%
- Veröffentlicht 22.02.2016 05:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping ...
CVE-2015-5268
- EPSS 0.28%
- Veröffentlicht 22.02.2016 05:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating va...
CVE-2015-5267
- EPSS 0.4%
- Veröffentlicht 22.02.2016 05:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attack...
CVE-2015-5266
- EPSS 0.25%
- Veröffentlicht 22.02.2016 05:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leverag...
CVE-2015-5265
- EPSS 0.27%
- Veröffentlicht 22.02.2016 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete a...