Vulnerabilities > Moodle > Moodle > 2.7.0

DATE CVE VULNERABILITY TITLE RISK
2014-07-29 CVE-2014-3542 Information Exposure vulnerability in Moodle
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
moodle CWE-200
4.3
2014-07-29 CVE-2014-3541 Code Injection vulnerability in Moodle
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.
network
low complexity
moodle CWE-94
7.5