Vulnerabilities > Moodle > Moodle > 3.2.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-09-18 | CVE-2017-12157 | Information Exposure vulnerability in Moodle In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access. | 4.0 |
2017-09-18 | CVE-2017-12156 | Cross-site Scripting vulnerability in Moodle Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback. | 4.3 |
2017-07-17 | CVE-2017-7532 | Improper Privilege Management vulnerability in Moodle In Moodle 3.x, course creators are able to change system default settings for courses. | 4.0 |
2017-07-17 | CVE-2017-2642 | Information Exposure vulnerability in Moodle Moodle 3.x has user fullname disclosure on the user preferences page. | 4.0 |