Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 2.2.7 vulnerabilities and exploits
(subscribe to this query)
5.8
CVSSv2
CVE-2012-6101
Multiple open redirect vulnerabilities in Moodle 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1 allow remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comm...
Moodle Moodle 2.2.2
Moodle Moodle 2.2.6
Moodle Moodle 2.2.1
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.3.1
Moodle Moodle 2.3.3
Moodle Moodle 2.3.2
Moodle Moodle 2.3.0
Moodle Moodle 2.4.0
5.5
CVSSv2
CVE-2014-0009
course/loginas.php in Moodle up to and including 2.2.11, 2.3.x prior to 2.3.11, 2.4.x prior to 2.4.8, 2.5.x prior to 2.5.4, and 2.6.x prior to 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, ...
Moodle Moodle 2.6.0
Moodle Moodle 2.3.8
Moodle Moodle 2.0.2
Moodle Moodle 2.3.4
Moodle Moodle 2.2.2
Moodle Moodle 2.3.1
Moodle Moodle 2.0.1
Moodle Moodle
Moodle Moodle 2.2.9
Moodle Moodle 2.1.2
Moodle Moodle 2.0.4
Moodle Moodle 2.2.6
Moodle Moodle 2.3.6
Moodle Moodle 2.1.10
Moodle Moodle 2.1.8
Moodle Moodle 2.3.10
Moodle Moodle 2.2.8
Moodle Moodle 2.1.9
Moodle Moodle 2.3.5
Moodle Moodle 2.0.3
Moodle Moodle 2.1.1
Moodle Moodle 2.1.5
5
CVSSv2
CVE-2014-0216
The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle up to and including 2.3.11, 2.4.x prior to 2.4.10, 2.5.x prior to 2.5.6, and 2.6.x prior to 2.6.3 does not properly restrict file access, which allows remote malicious users to obtai...
Moodle Moodle 2.3.8
Moodle Moodle 2.0.2
Moodle Moodle 2.5.1
Moodle Moodle 2.5.3
Moodle Moodle 2.3.4
Moodle Moodle 2.2.2
Moodle Moodle 2.3.1
Moodle Moodle 2.5.5
Moodle Moodle 2.6.1
Moodle Moodle 2.4.3
Moodle Moodle 2.4.1
Moodle Moodle 2.0.1
Moodle Moodle 2.5.2
Moodle Moodle 2.2.9
Moodle Moodle 2.4.9
Moodle Moodle 2.1.2
Moodle Moodle 2.4.2
Moodle Moodle 2.0.4
Moodle Moodle 2.2.6
Moodle Moodle 2.3.6
Moodle Moodle 2.4.6
Moodle Moodle 2.1.10
5
CVSSv2
CVE-2013-4522
lib/filelib.php in Moodle up to and including 2.2.11, 2.3.x prior to 2.3.10, 2.4.x prior to 2.4.7, and 2.5.x prior to 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote malicious users to obtain sensitive information by requesting a file that...
Moodle Moodle 2.3.8
Moodle Moodle 1.8.13
Moodle Moodle 2.0.2
Moodle Moodle 2.5.1
Moodle Moodle 1.9.4
Moodle Moodle 1.5.2
Moodle Moodle 2.3.4
Moodle Moodle 1.9.17
Moodle Moodle 2.2.2
Moodle Moodle 1.9.1
Moodle Moodle 1.8.8
Moodle Moodle 1.6.1
Moodle Moodle 2.3.1
Moodle Moodle 1.9.6
Moodle Moodle 1.8.2
Moodle Moodle 1.9.9
Moodle Moodle 1.2.1
Moodle Moodle 2.4.3
Moodle Moodle 1.4.2
Moodle Moodle 2.4.1
Moodle Moodle 1.6.8
Moodle Moodle 2.0.1
5
CVSSv2
CVE-2013-2082
Moodle up to and including 2.1.10, 2.2.x prior to 2.2.10, 2.3.x prior to 2.3.7, and 2.4.x prior to 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote malicious users to obtain sensitive information via a crafted request.
Moodle Moodle 2.1.2
Moodle Moodle 2.1.10
Moodle Moodle 2.1.8
Moodle Moodle 2.1.9
Moodle Moodle 2.1.1
Moodle Moodle 2.1.5
Moodle Moodle 2.1.6
Moodle Moodle 2.1.3
Moodle Moodle 2.1.7
Moodle Moodle 2.1.4
Moodle Moodle 2.1.0
Moodle Moodle 2.2.2
Moodle Moodle 2.2.9
Moodle Moodle 2.2.6
Moodle Moodle 2.2.8
Moodle Moodle 2.2.1
Moodle Moodle 2.2.7
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.3.4
5
CVSSv2
CVE-2013-2083
The MoodleQuickForm class in lib/formslib.php in Moodle up to and including 2.1.10, 2.2.x prior to 2.2.10, 2.3.x prior to 2.3.7, and 2.4.x prior to 2.4.4 does not properly handle a certain array-element syntax, which allows remote malicious users to bypass intended form-data filt...
Moodle Moodle 2.1.2
Moodle Moodle 2.1.10
Moodle Moodle 2.1.8
Moodle Moodle 2.1.9
Moodle Moodle 2.1.1
Moodle Moodle 2.1.5
Moodle Moodle 2.1.6
Moodle Moodle 2.1.3
Moodle Moodle 2.1.7
Moodle Moodle 2.1.4
Moodle Moodle 2.1.0
Moodle Moodle 2.2.2
Moodle Moodle 2.2.9
Moodle Moodle 2.2.6
Moodle Moodle 2.2.8
Moodle Moodle 2.2.1
Moodle Moodle 2.2.7
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.3.4
5
CVSSv2
CVE-2013-1831
lib/setuplib.php in Moodle up to and including 2.1.10, 2.2.x prior to 2.2.8, 2.3.x prior to 2.3.5, and 2.4.x prior to 2.4.2 allows remote malicious users to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.
Moodle Moodle 1.8.13
Moodle Moodle 2.0.2
Moodle Moodle 1.9.4
Moodle Moodle 1.5.2
Moodle Moodle 1.9.17
Moodle Moodle 1.9.1
Moodle Moodle 1.8.8
Moodle Moodle 1.6.1
Moodle Moodle 1.9.6
Moodle Moodle 1.8.2
Moodle Moodle 1.9.9
Moodle Moodle 1.2.1
Moodle Moodle 1.4.2
Moodle Moodle 1.6.8
Moodle Moodle 2.0.1
Moodle Moodle 1.6.5
Moodle Moodle 1.9.11
Moodle Moodle 2.1.2
Moodle Moodle 1.3.3
Moodle Moodle 1.4.3
Moodle Moodle 2.0.4
Moodle Moodle 1.4.5
5
CVSSv2
CVE-2013-1830
user/view.php in Moodle up to and including 2.1.10, 2.2.x prior to 2.2.8, 2.3.x prior to 2.3.5, and 2.4.x prior to 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote malicious users to obtain sensitive course-profile information by leveraging the guest ...
Fedoraproject Fedora 17
Fedoraproject Fedora 18
Moodle Moodle 2.2.2
Moodle Moodle 2.2.6
Moodle Moodle 2.2.1
Moodle Moodle 2.2.7
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.4.1
Moodle Moodle 2.4.0
Moodle Moodle 2.3.4
Moodle Moodle 2.3.1
Moodle Moodle 2.3.3
Moodle Moodle 2.3.2
Moodle Moodle 2.3.0
Moodle Moodle 1.8.13
Moodle Moodle 2.0.2
Moodle Moodle 1.9.4
Moodle Moodle 1.5.2
Moodle Moodle 1.9.17
5
CVSSv2
CVE-2012-6104
blog/rsslib.php in Moodle 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1 allows remote malicious users to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
Moodle Moodle 2.2.2
Moodle Moodle 2.2.6
Moodle Moodle 2.2.1
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.3.1
Moodle Moodle 2.3.3
Moodle Moodle 2.3.2
Moodle Moodle 2.3.0
Moodle Moodle 2.4.0
5
CVSSv2
CVE-2012-6105
blog/rsslib.php in Moodle 2.1.x prior to 2.1.10, 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote malicious users to obtain sensitive information by reading this feed.
Moodle Moodle 2.1.2
Moodle Moodle 2.1.8
Moodle Moodle 2.1.9
Moodle Moodle 2.1.1
Moodle Moodle 2.1.5
Moodle Moodle 2.1.6
Moodle Moodle 2.1.3
Moodle Moodle 2.1.7
Moodle Moodle 2.1.4
Moodle Moodle 2.1.0
Moodle Moodle 2.2.2
Moodle Moodle 2.2.6
Moodle Moodle 2.2.1
Moodle Moodle 2.2.3
Moodle Moodle 2.2.5
Moodle Moodle 2.2.4
Moodle Moodle 2.2.0
Moodle Moodle 2.3.1
Moodle Moodle 2.3.3
Moodle Moodle 2.3.2
Moodle Moodle 2.3.0
Moodle Moodle 2.4.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »