- EPSS 0.46%
- Veröffentlicht 17.07.2012 10:20:52
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.
- EPSS 0.32%
- Veröffentlicht 17.07.2012 10:20:52
- Zuletzt bearbeitet 11.04.2025 00:51:21
The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic pro...
CVE-2011-4293
- EPSS 0.2%
- Veröffentlicht 16.07.2012 10:28:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an opera...
CVE-2011-4294
- EPSS 0.4%
- Veröffentlicht 16.07.2012 10:28:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick user...
CVE-2011-4295
- EPSS 0.44%
- Veröffentlicht 16.07.2012 10:28:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.
CVE-2011-4296
- EPSS 0.44%
- Veröffentlicht 16.07.2012 10:28:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
CVE-2011-4297
- EPSS 0.52%
- Veröffentlicht 16.07.2012 10:28:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.
CVE-2011-4133
- EPSS 0.13%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
CVE-2011-4278
- EPSS 0.3%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.28%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demon...