Vulnerabilities > Moodle > Moodle > 2.8.0

DATE CVE VULNERABILITY TITLE RISK
2015-06-01 CVE-2015-3177 Code vulnerability in Moodle
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
network
moodle CWE-17
3.5
2015-06-01 CVE-2015-3176 Information Exposure vulnerability in Moodle
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.
network
moodle CWE-200
4.3
2015-06-01 CVE-2015-3175 Unspecified vulnerability in Moodle
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.
network
moodle
5.8
2015-06-01 CVE-2015-3174 Cross-site Scripting vulnerability in Moodle
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
network
moodle CWE-79
3.5
2015-06-01 CVE-2015-2273 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the student role for a crafted quiz response.
network
moodle CWE-79
3.5
2015-06-01 CVE-2015-2272 Permissions, Privileges, and Access Controls vulnerability in Moodle
login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass a forced-password-change requirement by creating a web-services token.
network
low complexity
moodle CWE-264
4.0
2015-06-01 CVE-2015-2271 Permissions, Privileges, and Access Controls vulnerability in Moodle
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
network
low complexity
moodle CWE-264
4.0
2015-06-01 CVE-2015-2270 Code vulnerability in Moodle
lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain sensitive course information via unspecified vectors.
network
moodle CWE-17
4.3
2015-06-01 CVE-2015-2269 Cross-site Scripting vulnerability in Moodle
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.
network
moodle CWE-79
3.5
2015-06-01 CVE-2015-2268 Resource Management Errors vulnerability in Moodle
filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.
network
low complexity
moodle CWE-399
6.8