Vulnerabilities > Moodle > Moodle > 2.2.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-01-27 | CVE-2012-6098 | Permissions, Privileges, and Access Controls vulnerability in Moodle grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature. | 4.0 |
2012-11-21 | CVE-2012-5480 | Permissions, Privileges, and Access Controls vulnerability in Moodle The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search. | 6.4 |
2012-11-21 | CVE-2012-5479 | Permissions, Privileges, and Access Controls vulnerability in Moodle The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback. | 6.5 |
2012-11-21 | CVE-2012-5473 | Information Exposure vulnerability in Moodle The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search. | 4.0 |
2012-11-21 | CVE-2012-5472 | Permissions, Privileges, and Access Controls vulnerability in Moodle lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field. | 4.0 |
2012-11-21 | CVE-2012-5471 | Permissions, Privileges, and Access Controls vulnerability in Moodle The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout. | 6.5 |
2012-09-19 | CVE-2012-4408 | Permissions, Privileges, and Access Controls vulnerability in Moodle course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation. | 5.5 |
2012-09-19 | CVE-2012-4407 | Information Exposure vulnerability in Moodle lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file. | 5.0 |
2012-09-19 | CVE-2012-4402 | Permissions, Privileges, and Access Controls vulnerability in Moodle webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | 4.9 |
2012-09-19 | CVE-2012-4401 | Permissions, Privileges, and Access Controls vulnerability in Moodle Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities. | 4.0 |