Vulnerabilities > Moodle > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-10 CVE-2018-10891 Unspecified vulnerability in Moodle
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13.
network
low complexity
moodle
7.3
2018-05-25 CVE-2018-1137 Improper Input Validation vulnerability in Moodle
An issue was discovered in Moodle 3.x.
network
low complexity
moodle CWE-20
8.1
2018-05-25 CVE-2018-1133 Code Injection vulnerability in Moodle
An issue was discovered in Moodle 3.x.
network
low complexity
moodle CWE-94
8.8
2018-04-04 CVE-2018-1082 Improper Authentication vulnerability in Moodle
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4.
network
high complexity
moodle CWE-287
8.1
2017-04-20 CVE-2016-3734 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
network
low complexity
moodle CWE-352
8.8
2017-01-20 CVE-2016-7038 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Moodle
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
network
low complexity
moodle CWE-640
7.3
2016-11-04 CVE-2016-9187 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
8.8
2016-11-04 CVE-2016-9186 Unrestricted Upload of File with Dangerous Type vulnerability in Moodle
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
network
low complexity
moodle CWE-434
8.8
2016-10-28 CVE-2016-7919 SQL Injection vulnerability in Moodle 3.1.2
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component.
network
low complexity
moodle CWE-89
7.5
2016-05-22 CVE-2016-2157 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
network
low complexity
moodle CWE-352
8.8