Vulnerabilities > Moodle > Moodle > 2.4.4

DATE CVE VULNERABILITY TITLE RISK
2013-07-29 CVE-2013-2244 Cross-Site Scripting vulnerability in Moodle
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
network
moodle CWE-79
4.3
2013-07-29 CVE-2013-2243 Information Exposure vulnerability in Moodle
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
network
low complexity
moodle CWE-200
4.0
2013-07-29 CVE-2013-2242 Permissions, Privileges, and Access Controls vulnerability in Moodle
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.
network
low complexity
moodle CWE-264
4.0