Vulnerabilities > Moodle > Moodle > 2.4.8

DATE CVE VULNERABILITY TITLE RISK
2014-03-24 CVE-2014-0123 Permissions, Privileges, and Access Controls vulnerability in Moodle
The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
network
moodle CWE-264
4.9
2014-03-24 CVE-2014-0122 Permissions, Privileges, and Access Controls vulnerability in Moodle
mod/chat/chat_ajax.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly check for the mod/chat:chat capability during chat sessions, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by remaining in a chat session after an intra-session capability removal by an administrator.
network
moodle CWE-264
4.9
2014-03-24 CVE-2013-7341 Cross-Site Scripting vulnerability in multiple products
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
4.3
2013-11-01 CVE-2013-3630 Code Injection vulnerability in Moodle
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
network
high complexity
moodle CWE-94
4.6