Vulnerabilities > Moodle > Moodle > 2.8.0

DATE CVE VULNERABILITY TITLE RISK
2015-06-01 CVE-2015-2267 Improper Access Control vulnerability in Moodle
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.
network
low complexity
moodle CWE-284
4.0
2015-06-01 CVE-2015-2266 Information Exposure vulnerability in Moodle
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.
network
low complexity
moodle CWE-200
4.0
2015-06-01 CVE-2015-0218 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
network
moodle CWE-352
6.8
2015-06-01 CVE-2015-0217 Resource Management Errors vulnerability in Moodle
filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.
network
low complexity
moodle CWE-399
6.8
2015-06-01 CVE-2015-0216 Cross-site Scripting vulnerability in Moodle 2.8.0/2.8.1
access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.
network
moodle CWE-79
3.5
2015-06-01 CVE-2015-0215 Information Exposure vulnerability in Moodle
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.
network
low complexity
moodle CWE-200
4.0
2015-06-01 CVE-2015-0214 Permissions, Privileges, and Access Controls vulnerability in Moodle
message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.
network
low complexity
moodle CWE-264
4.0
2015-06-01 CVE-2015-0213 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.
network
moodle CWE-352
6.8
2015-06-01 CVE-2015-0212 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.
network
moodle CWE-79
3.5
2015-06-01 CVE-2015-0211 Information Exposure vulnerability in Moodle
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
network
low complexity
moodle CWE-200
4.0