Vulnerabilities > Moodle > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-11-24 CVE-2014-7848 Information Exposure vulnerability in Moodle
lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
network
low complexity
moodle CWE-200
5.0
2014-11-24 CVE-2014-7847 Resource Management Errors vulnerability in Moodle
iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.
network
low complexity
moodle CWE-399
5.0
2014-11-24 CVE-2014-7846 Permissions, Privileges, and Access Controls vulnerability in Moodle
tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.
network
low complexity
moodle CWE-264
4.0
2014-11-24 CVE-2014-7838 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.
network
moodle CWE-352
6.8
2014-11-24 CVE-2014-7837 Permissions, Privileges, and Access Controls vulnerability in Moodle
mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.
network
low complexity
moodle CWE-264
5.5
2014-11-24 CVE-2014-7836 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.
network
moodle CWE-352
6.8
2014-11-24 CVE-2014-7834 Permissions, Privileges, and Access Controls vulnerability in Moodle
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.
network
low complexity
moodle CWE-264
4.0
2014-11-24 CVE-2014-7833 Information Exposure vulnerability in Moodle
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.
network
low complexity
moodle CWE-200
4.0
2014-11-24 CVE-2014-7832 Permissions, Privileges, and Access Controls vulnerability in Moodle
mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.
network
low complexity
moodle CWE-264
4.0
2014-11-24 CVE-2014-7831 Information Exposure vulnerability in Moodle
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.
network
low complexity
moodle CWE-200
4.0