moodle

629 tracked vulnerabilities.

CVE-2012-4401
Moodle 2.2.x < 2.2.5 and 2.3.x < 2.3.2 - Authenticated Capability Restriction Bypass
Sep 19, 2012
EPSS 0.00
CVE-2012-4400
Moodle 2.2.x < 2.2.5 and 2.3.x < 2.3.2 - Authenticated Upload Size Restriction Bypass via maxbytes Field
Sep 19, 2012
EPSS 0.00
CVE-2012-3398
Moodle 1.9.x-1.9.19 2.0.x-2.0.10 2.1.x-2.1.7 2.2.x-2.2.4 - Authenticated Denial of Service via Advanced Search
Jul 23, 2012
EPSS 0.01
CVE-2012-3397
Moodle 2.0.x-2.0.10 2.1.x-2.1.7 2.2.x-2.2.4 2.3.x-2.3.1 - Authenticated Access Restriction Bypass via Activity Selection
Jul 23, 2012
EPSS 0.00
CVE-2012-3396
Moodle 2.0.x-2.0.10, 2.1.x-2.1.7, 2.2.x-2.2.4, 2.3.x-2.3.1 - XSS via Cohort ID Field
Jul 23, 2012
EPSS 0.00
CVE-2012-3395
Moodle 2.0.x-2.0.10, 2.1.x-2.1.7, 2.2.x-2.2.4 - Authenticated SQL Injection via Feedback Form Data
Jul 23, 2012
EPSS 0.00
CVE-2012-3394
Moodle 2.0.x-2.0.10, 2.1.x-2.1.7, 2.2.x-2.2.4, 2.3.x-2.3.1 - Sensitive Info Exposure via LDAP Redirect
Jul 23, 2012
EPSS 0.00
CVE-2012-3393
Moodle 2.1.x < 2.1.7 and 2.2.x < 2.2.4 - Authenticated Cross-Site Scripting via Repository Rename
Jul 23, 2012
EPSS 0.00
CVE-2012-3392
Moodle <2.1.7 & <2.2.4 - Auth Bypass
Jul 23, 2012
EPSS 0.00
CVE-2012-3391
Moodle 2.1.x-2.1.7 and 2.2.x-2.2.4 - Authenticated Access Restriction Bypass via RSS Feed
Jul 23, 2012
EPSS 0.00
CVE-2012-3390
Moodle 2.1.x-2.1.7 and 2.2.x-2.2.4 - Authenticated Information Disclosure via Hidden Block File Access
Jul 23, 2012
EPSS 0.00
CVE-2012-3389
Moodle 2.2.x < 2.2.4 and 2.3.x < 2.3.1 - Cross-Site Scripting via lti_typename or lti_toolurl Parameter
Jul 23, 2012
EPSS 0.00
CVE-2012-3388
Moodle 2.2.x < 2.2.4 and 2.3.x < 2.3.1 - Authenticated Capability Check Bypass via Caching
Jul 23, 2012
EPSS 0.00
CVE-2012-3387
Moodle 2.3.x < 2.3.1 - Authenticated File Upload Restriction Bypass
Jul 23, 2012
EPSS 0.00
CVE-2012-2367
Moodle 1.9.x < 1.9.18, 2.0.x < 2.0.9, 2.1.x < 2.1.6, 2.2.x < 2.2.3 - Authenticated Capability Bypass via Calendar Entry
Jul 21, 2012
EPSS 0.00
CVE-2012-2366
Moodle <2.1.6 & <2.2.3 - Info Disclosure
Jul 21, 2012
EPSS 0.00
CVE-2012-2365
Moodle 2.0.x-2.0.9, 2.1.x-2.1.6, 2.2.x-2.2.3 - Authenticated Cross-Site Scripting via Cohort ID Number Field
Jul 21, 2012
EPSS 0.00
CVE-2012-2364
Moodle 2.0.x < 2.0.9, 2.1.x < 2.1.6, 2.2.x < 2.2.3 - Authenticated Cross-Site Scripting via Assignment Submission
Jul 21, 2012
EPSS 0.00
CVE-2012-2363
Moodle 1.9.x < 1.9.18 - Authenticated SQL Injection via Calendar Event
Jul 21, 2012
EPSS 0.00
CVE-2012-2362
Moodle 1.9.x < 1.9.18 - Cross-Site Scripting in Blog Index Parameter
Jul 21, 2012
EPSS 0.00
CVE-2012-2361
Moodle 2.0.x-2.0.8, 2.1.x-2.1.5, 2.2.x-2.2.2 - Authenticated Cross-Site Scripting via Web Service Name Field
Jul 21, 2012
EPSS 0.00
CVE-2012-2360
Moodle 2.0.x-2.0.8, 2.1.x-2.1.5, 2.2.x-2.2.2 - Authenticated Cross-Site Scripting via Wiki Page Title
Jul 21, 2012
EPSS 0.00
CVE-2012-2359
Moodle <2.0.9, <2.1.6, <2.2.3 - Privilege Escalation
Jul 21, 2012
EPSS 0.00
CVE-2012-2358
Moodle <2.0.9-<2.1.6-<2.2.3 - Privilege Escalation
Jul 21, 2012
EPSS 0.00
CVE-2012-2357
Moodle <2.1.6-2.2.3 - Info Disclosure
Jul 21, 2012
EPSS 0.00