Vulnerabilities > Moodle > Moodle > 2.8

DATE CVE VULNERABILITY TITLE RISK
2019-03-26 CVE-2019-3848 Incorrect Authorization vulnerability in Moodle
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8.
network
low complexity
moodle CWE-863
4.3
2018-11-26 CVE-2018-16854 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier.
network
moodle CWE-352
6.8
2018-09-17 CVE-2018-14630 Code Injection vulnerability in Moodle
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution.
network
low complexity
moodle CWE-94
6.5
2018-04-04 CVE-2018-1081 Unspecified vulnerability in Moodle
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions.
network
low complexity
moodle
5.0
2018-01-22 CVE-2018-1045 Cross-site Scripting vulnerability in Moodle
In Moodle 3.x, there is XSS via a calendar event name.
network
moodle CWE-79
3.5
2018-01-22 CVE-2018-1044 Information Exposure vulnerability in Moodle
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.
network
low complexity
moodle CWE-200
4.0
2018-01-22 CVE-2018-1042 Server-Side Request Forgery (SSRF) vulnerability in Moodle
Moodle 3.x has Server Side Request Forgery in the filepicker.
network
low complexity
moodle CWE-918
4.0
2017-11-20 CVE-2017-15110 Information Exposure vulnerability in Moodle
In Moodle 3.x, students can find out email addresses of other students in the same course.
network
low complexity
moodle CWE-200
4.0
2016-11-04 CVE-2016-9188 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
network
moodle CWE-79
4.3
2016-11-04 CVE-2016-9187 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
6.5