Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID number...

  • EPSS 0.14%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access ...

  • EPSS 0.36%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML...

  • EPSS 0.16%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which...

  • EPSS 0.2%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

  • EPSS 0.2%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

  • EPSS 0.16%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.

  • EPSS 0.41%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these ...

  • EPSS 0.24%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET singl...

  • EPSS 0.39%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.