Vulnerabilities > Moodle > Moodle > 2.3

DATE CVE VULNERABILITY TITLE RISK
2014-05-27 CVE-2014-0216 Permissions, Privileges, and Access Controls vulnerability in Moodle
The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.
network
low complexity
moodle CWE-264
5.0
2014-05-27 CVE-2014-0215 Information Exposure vulnerability in Moodle
The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.
network
low complexity
moodle CWE-200
4.0
2014-05-27 CVE-2014-0214 Improper Authentication vulnerability in Moodle
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
network
moodle CWE-287
6.8
2014-05-27 CVE-2014-0213 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.
network
moodle CWE-352
6.8
2014-03-24 CVE-2014-2571 Cross-Site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.
network
moodle CWE-79
3.5
2014-03-24 CVE-2014-0129 Permissions, Privileges, and Access Controls vulnerability in Moodle
badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.
network
low complexity
moodle CWE-264
4.0
2014-03-24 CVE-2014-0127 Permissions, Privileges, and Access Controls vulnerability in Moodle
The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.
network
moodle CWE-264
4.9
2014-03-24 CVE-2014-0126 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
network
moodle CWE-352
6.8
2014-03-24 CVE-2014-0125 Permissions, Privileges, and Access Controls vulnerability in Moodle
repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.
network
moodle CWE-264
5.8
2014-03-24 CVE-2014-0124 Permissions, Privileges, and Access Controls vulnerability in Moodle
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
network
low complexity
moodle CWE-264
4.0