Vulnerabilities > Moodle > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-22 CVE-2018-1042 Server-Side Request Forgery (SSRF) vulnerability in Moodle
Moodle 3.x has Server Side Request Forgery in the filepicker.
network
low complexity
moodle CWE-918
6.5
2017-11-20 CVE-2017-15110 Information Exposure vulnerability in Moodle
In Moodle 3.x, students can find out email addresses of other students in the same course.
network
low complexity
moodle CWE-200
4.3
2017-09-18 CVE-2017-12157 Information Exposure vulnerability in Moodle
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
network
low complexity
moodle CWE-200
4.3
2017-09-18 CVE-2017-12156 Cross-site Scripting vulnerability in Moodle
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
network
low complexity
moodle CWE-79
6.1
2017-07-17 CVE-2017-7532 Improper Privilege Management vulnerability in Moodle
In Moodle 3.x, course creators are able to change system default settings for courses.
network
low complexity
moodle CWE-269
6.5
2017-07-17 CVE-2017-7531 Information Exposure vulnerability in Moodle 3.3.0
In Moodle 3.3, the course overview block reveals activities in hidden courses.
network
low complexity
moodle CWE-200
4.3
2017-07-17 CVE-2017-2642 Information Exposure vulnerability in Moodle
Moodle 3.x has user fullname disclosure on the user preferences page.
network
low complexity
moodle CWE-200
6.5
2017-05-15 CVE-2017-7491 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
network
low complexity
moodle CWE-352
4.3
2017-05-15 CVE-2017-7490 Exposure of Resource to Wrong Sphere vulnerability in Moodle
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
network
low complexity
moodle CWE-668
5.3
2017-05-15 CVE-2017-7489 Improper Privilege Management vulnerability in Moodle
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
network
low complexity
moodle CWE-269
6.3