Vulnerabilities > Moodle > Moodle > 2.8.0

DATE CVE VULNERABILITY TITLE RISK
2016-02-22 CVE-2015-5266 Permissions, Privileges, and Access Controls vulnerability in Moodle
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
network
moodle CWE-264
4.9
2016-02-22 CVE-2015-5265 Permissions, Privileges, and Access Controls vulnerability in Moodle
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
network
low complexity
moodle CWE-264
4.0
2016-02-22 CVE-2015-5264 Permissions, Privileges, and Access Controls vulnerability in Moodle
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
network
low complexity
moodle CWE-264
5.5
2016-02-22 CVE-2015-3275 Cross-site Scripting vulnerability in Moodle
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
network
moodle CWE-79
4.3
2016-02-22 CVE-2015-3274 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.
network
moodle CWE-79
4.3
2016-02-22 CVE-2015-3272 Unspecified vulnerability in Moodle
Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.
network
moodle
5.8
2015-06-01 CVE-2015-3181 Permissions, Privileges, and Access Controls vulnerability in Moodle
files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.
network
low complexity
moodle CWE-264
4.0
2015-06-01 CVE-2015-3180 Information Exposure vulnerability in Moodle
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
network
low complexity
moodle CWE-200
4.0
2015-06-01 CVE-2015-3179 Permissions, Privileges, and Access Controls vulnerability in Moodle
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
network
moodle CWE-264
3.5
2015-06-01 CVE-2015-3178 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
network
moodle CWE-79
3.5