Vulnerabilities > Moodle > Moodle > 2.8.1

DATE CVE VULNERABILITY TITLE RISK
2016-11-04 CVE-2016-9188 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
network
moodle CWE-79
4.3
2016-11-04 CVE-2016-9187 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
6.5
2016-11-04 CVE-2016-9186 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
6.5
2016-05-22 CVE-2016-2190 Permissions, Privileges, and Access Controls vulnerability in Moodle
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
network
low complexity
moodle CWE-264
5.0
2016-05-22 CVE-2016-2159 Improper Access Control vulnerability in Moodle
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request.
network
low complexity
moodle CWE-284
4.0
2016-05-22 CVE-2016-2158 Information Exposure vulnerability in Moodle
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.
network
low complexity
moodle CWE-200
4.0
2016-05-22 CVE-2016-2157 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
network
moodle CWE-352
6.8
2016-05-22 CVE-2016-2156 Information Exposure vulnerability in Moodle
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.
network
low complexity
moodle CWE-200
4.0
2016-05-22 CVE-2016-2155 Permissions, Privileges, and Access Controls vulnerability in Moodle
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
network
low complexity
moodle CWE-264
4.0
2016-05-22 CVE-2016-2154 Information Exposure vulnerability in Moodle
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.
network
low complexity
moodle CWE-200
4.0