Search CVE reports


Toggle filters

311 – 320 of 672 results


CVE-2017-15110

Medium priority
Not affected

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — —
Show less packages

CVE-2017-12157

Medium priority
Vulnerable

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-12156

Medium priority
Vulnerable

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7532

Medium priority
Vulnerable

In Moodle 3.x, course creators are able to change system default settings for courses.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7531

Medium priority
Vulnerable

In Moodle 3.3, the course overview block reveals activities in hidden courses.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-2642

Medium priority
Vulnerable

Moodle 3.x has user fullname disclosure on the user preferences page.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7491

Low priority
Vulnerable

In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7490

Medium priority
Vulnerable

In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-7489

Medium priority
Vulnerable

In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2016-3734

Medium priority
Ignored

Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for...

1 affected package

moodle

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle — — — — Not affected
Show less packages