Moodle

Moodle

624 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks ...

  • EPSS 0.67%
  • Veröffentlicht 20.07.2012 10:40:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible ex...

  • EPSS 0.61%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

  • EPSS 0.2%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors i...

  • EPSS 0.14%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

  • EPSS 0.27%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

  • EPSS 0.28%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

  • EPSS 0.07%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated b...

  • EPSS 0.4%
  • Veröffentlicht 17.07.2012 10:20:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

  • EPSS 0.23%
  • Veröffentlicht 17.07.2012 10:20:52
  • Zuletzt bearbeitet 11.04.2025 00:51:21

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.