- EPSS 0.15%
- Published 21.11.2012 12:55:03
- Last modified 11.04.2025 00:51:21
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
CVE-2012-5471
- EPSS 0.5%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.
- EPSS 0.23%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
- EPSS 0.15%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
- EPSS 0.15%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
CVE-2012-4402
- EPSS 0.18%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token inte...
- EPSS 0.28%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading ...
- EPSS 0.28%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that reference...
CVE-2012-4408
- EPSS 0.17%
- Published 19.09.2012 10:57:07
- Last modified 11.04.2025 00:51:21
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
- EPSS 0.62%
- Published 23.07.2012 21:55:05
- Last modified 11.04.2025 00:51:21
Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature ...