Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 27.05.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-fo...

  • EPSS 0.2%
  • Veröffentlicht 27.05.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML sourc...

  • EPSS 0.28%
  • Veröffentlicht 27.05.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to...

  • EPSS 0.28%
  • Veröffentlicht 27.05.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by levera...

  • EPSS 0.26%
  • Veröffentlicht 27.05.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HT...

  • EPSS 0.26%
  • Veröffentlicht 24.03.2014 14:20:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by ...

  • EPSS 0.17%
  • Veröffentlicht 24.03.2014 14:20:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod/chat/chat_ajax.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly check for the mod/chat:chat capability during chat sessions, which allows remote authenticated users to bypass intended ...

  • EPSS 0.19%
  • Veröffentlicht 24.03.2014 14:20:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the ...

  • EPSS 0.2%
  • Veröffentlicht 24.03.2014 14:20:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which a...

  • EPSS 0.2%
  • Veröffentlicht 24.03.2014 14:20:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonatin...