Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 21.11.2012 12:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

  • EPSS 0.58%
  • Veröffentlicht 21.11.2012 12:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

  • EPSS 0.3%
  • Veröffentlicht 21.11.2012 12:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

  • EPSS 0.15%
  • Veröffentlicht 21.11.2012 12:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

  • EPSS 0.5%
  • Veröffentlicht 21.11.2012 12:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

  • EPSS 0.17%
  • Veröffentlicht 21.11.2012 12:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

  • EPSS 0.15%
  • Veröffentlicht 19.09.2012 10:57:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

  • EPSS 0.15%
  • Veröffentlicht 19.09.2012 10:57:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

  • EPSS 0.18%
  • Veröffentlicht 19.09.2012 10:57:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token inte...

  • EPSS 0.28%
  • Veröffentlicht 19.09.2012 10:57:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading ...