Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2017-01-20 CVE-2016-5014 Information Exposure vulnerability in Moodle
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
network
low complexity
moodle CWE-200
5.4
2017-01-20 CVE-2016-5013 Injection vulnerability in Moodle
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
network
low complexity
moodle CWE-74
5.4
2017-01-20 CVE-2016-5012 Information Exposure vulnerability in Moodle 3.1.0
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
network
low complexity
moodle CWE-200
5.3
2016-11-04 CVE-2016-9188 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
network
low complexity
moodle CWE-79
6.1
2016-11-04 CVE-2016-9187 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
8.8
2016-11-04 CVE-2016-9186 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
8.8
2016-10-28 CVE-2016-7919 SQL Injection vulnerability in Moodle 3.1.2
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component.
network
low complexity
moodle CWE-89
7.5
2016-05-22 CVE-2016-2190 Permissions, Privileges, and Access Controls vulnerability in Moodle
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
network
low complexity
moodle CWE-264
5.3
2016-05-22 CVE-2016-2159 Improper Access Control vulnerability in Moodle
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request.
network
low complexity
moodle CWE-284
4.3
2016-05-22 CVE-2016-2158 Information Exposure vulnerability in Moodle
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.
network
low complexity
moodle CWE-200
4.3