Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2016-02-22 CVE-2015-5337 Cross-site Scripting vulnerability in Moodle
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
network
low complexity
moodle CWE-79
6.1
2016-02-22 CVE-2015-5336 Cross-site Scripting vulnerability in Moodle
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
network
low complexity
moodle CWE-79
5.4
2016-02-22 CVE-2015-5335 Information Exposure vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.
network
low complexity
moodle CWE-200
4.3
2016-02-22 CVE-2015-5332 Resource Management Errors vulnerability in Moodle
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
network
high complexity
moodle CWE-399
6.8
2016-02-22 CVE-2015-5331 7PK - Security Features vulnerability in Moodle 2.9.0/2.9.1/2.9.2
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
network
low complexity
moodle CWE-254
4.3
2016-02-22 CVE-2015-5272 Permissions, Privileges, and Access Controls vulnerability in Moodle
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
network
low complexity
moodle CWE-264
4.3
2016-02-22 CVE-2015-5269 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
network
low complexity
moodle CWE-79
5.4
2016-02-22 CVE-2015-5268 Information Exposure vulnerability in Moodle
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
network
low complexity
moodle CWE-200
4.3
2016-02-22 CVE-2015-5267 7PK - Security Features vulnerability in Moodle
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
network
low complexity
moodle CWE-254
7.5
2016-02-22 CVE-2015-5266 Permissions, Privileges, and Access Controls vulnerability in Moodle
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
network
high complexity
moodle CWE-264
6.8