CVE-2011-4290
- EPSS 1.2%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 16.06.2026 23:34:42
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
- EPSS 1.92%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 16.06.2026 23:34:42
Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.
- EPSS 1.99%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 16.06.2026 23:34:42
Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.
- EPSS 1.72%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
- EPSS 1.92%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
CVE-2011-4306
- EPSS 1.83%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
CVE-2011-4307
- EPSS 1.19%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
- EPSS 1.67%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
- EPSS 1.43%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 16.06.2026 23:34:44
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
CVE-2011-4298
- EPSS 1.01%
- Veröffentlicht 11.07.2012 10:26:10
- Zuletzt bearbeitet 16.06.2026 23:34:43
Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.