- EPSS 0.28%
- Veröffentlicht 19.09.2012 10:57:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that reference...
CVE-2012-4408
- EPSS 0.17%
- Veröffentlicht 19.09.2012 10:57:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
- EPSS 0.62%
- Veröffentlicht 23.07.2012 21:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature ...
- EPSS 0.2%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.
- EPSS 0.2%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified...
CVE-2012-3389
- EPSS 0.3%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.
CVE-2012-3390
- EPSS 0.25%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a ...
- EPSS 0.22%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging ...
CVE-2012-3392
- EPSS 0.3%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsub...
CVE-2012-3393
- EPSS 0.23%
- Veröffentlicht 23.07.2012 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.