Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 24.11.2014 11:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via ...

  • EPSS 0.32%
  • Veröffentlicht 24.11.2014 11:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 ch...

  • EPSS 0.39%
  • Veröffentlicht 24.11.2014 11:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

  • EPSS 0.73%
  • Veröffentlicht 24.11.2014 11:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitu...

  • EPSS 0.24%
  • Veröffentlicht 24.11.2014 11:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access ...

  • EPSS 0.71%
  • Veröffentlicht 24.11.2014 11:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-f...

  • EPSS 0.17%
  • Veröffentlicht 24.11.2014 11:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for request...

  • EPSS 0.61%
  • Veröffentlicht 24.11.2014 11:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

  • EPSS 0.17%
  • Veröffentlicht 24.11.2014 11:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod...

  • EPSS 0.18%
  • Veröffentlicht 24.11.2014 11:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross...