Vulnerabilities > Moodle > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-02-22 | CVE-2015-5340 | Information Exposure vulnerability in Moodle Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php. | 4.3 |
2016-02-22 | CVE-2015-5339 | Information Exposure vulnerability in Moodle The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request. | 4.3 |
2016-02-22 | CVE-2015-5337 | Cross-site Scripting vulnerability in Moodle Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file. | 6.1 |
2016-02-22 | CVE-2015-5336 | Cross-site Scripting vulnerability in Moodle Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer. | 5.4 |
2016-02-22 | CVE-2015-5335 | Information Exposure vulnerability in Moodle Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL. | 4.3 |
2016-02-22 | CVE-2015-5332 | Resource Management Errors vulnerability in Moodle Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | 6.8 |
2016-02-22 | CVE-2015-5331 | 7PK - Security Features vulnerability in Moodle 2.9.0/2.9.1/2.9.2 Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API. | 4.3 |
2016-02-22 | CVE-2015-5272 | Permissions, Privileges, and Access Controls vulnerability in Moodle The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants." | 4.3 |
2016-02-22 | CVE-2015-5269 | Cross-site Scripting vulnerability in Moodle Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description. | 5.4 |
2016-02-22 | CVE-2015-5268 | Information Exposure vulnerability in Moodle The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value. | 4.3 |