Vulnerabilities > Moodle > Moodle > 2.2.0

DATE CVE VULNERABILITY TITLE RISK
2012-07-17 CVE-2012-0798 Permissions, Privileges, and Access Controls vulnerability in Moodle
The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.
network
low complexity
moodle CWE-264
5.5
2012-07-17 CVE-2012-0795 Improper Input Validation vulnerability in Moodle
Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.
network
low complexity
moodle CWE-20
6.5
2011-12-22 CVE-2011-4203 Code Injection vulnerability in Moodle
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.
network
low complexity
moodle CWE-94
5.0