Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 2.7.3 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2015-5272
The Forum module in Moodle 2.7.x prior to 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
6.1
CVSSv3
CVE-2015-3275
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.9, 2.8.x prior to 2.8.7, and 2.9.x prior to 2.9.1 allow remote malicious users to inject arbitrary web script or HTML via a crafted organization name t...
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
5.4
CVSSv3
CVE-2015-5264
The lesson module in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
4.3
CVSSv3
CVE-2015-5265
The wiki component in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary fil...
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
6.8
CVSSv3
CVE-2015-5266
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrec...
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.4
Moodle Moodle 2.7.3
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.8
Moodle Moodle 2.7.7
Moodle Moodle 2.7.0
Moodle Moodle
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.2
Moodle Moodle 2.7.1
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.6
Moodle Moodle 2.7.5
7.5
CVSSv3
CVE-2015-5267
lib/moodlelib.php in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote malicious users to...
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.7.2
Moodle Moodle 2.7.1
Moodle Moodle 2.8.5
Moodle Moodle 2.8.4
Moodle Moodle 2.7.6
Moodle Moodle 2.7.5
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
Moodle Moodle 2.7.4
Moodle Moodle 2.7.3
Moodle Moodle 2.8.7
Moodle Moodle 2.8.6
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.7
Moodle Moodle 2.7.0
Moodle Moodle
4.3
CVSSv3
CVE-2015-5268
The rating component in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.8.7
Moodle Moodle 2.8.6
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.5
Moodle Moodle 2.8.4
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
5.4
CVSSv3
CVE-2015-5269
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.2
Moodle Moodle 2.7.1
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.6
Moodle Moodle 2.7.5
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.4
Moodle Moodle 2.7.3
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.8
Moodle Moodle 2.7.7
Moodle Moodle 2.7.0
Moodle Moodle
NA
CVE-2015-0211
mod/lti/ajax.php in Moodle up to and including 2.5.9, 2.6.x prior to 2.6.7, 2.7.x prior to 2.7.4, and 2.8.x prior to 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows ...
Moodle Moodle 2.5.0
Moodle Moodle 2.6.6
Moodle Moodle 2.6.5
Moodle Moodle 2.6.4
Moodle Moodle 2.5.5
Moodle Moodle 2.5.3
Moodle Moodle 2.5.1
Moodle Moodle 2.6.3
Moodle Moodle 2.6.1
Moodle Moodle
Moodle Moodle 2.5.8
Moodle Moodle 2.5.7
Moodle Moodle 2.5.6
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.5.4
Moodle Moodle 2.5.2
Moodle Moodle 2.6.2
Moodle Moodle 2.6.0
Moodle Moodle 2.8.0
NA
CVE-2015-0213
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle up to and including 2.5.9, 2.6.x prior to 2.6.7, 2.7.x prior to 2.7.4, and 2.8.x prior to 2.8.2 allow remote malicious users to hijack...
Moodle Moodle 2.5.7
Moodle Moodle 2.5.6
Moodle Moodle 2.5.5
Moodle Moodle 2.5.4
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.0
Moodle Moodle 2.6.5
Moodle Moodle 2.6.4
Moodle Moodle 2.6.3
Moodle Moodle 2.6.2
Moodle Moodle 2.5.8
Moodle Moodle 2.5.3
Moodle Moodle 2.5.1
Moodle Moodle 2.6.6
Moodle Moodle 2.6.1
Moodle Moodle 2.7.3
Moodle Moodle
Moodle Moodle 2.5.2
Moodle Moodle 2.5.0
Moodle Moodle 2.6.0
Moodle Moodle 2.7.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »