Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 2.0.2 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2011-4284
Moodle 2.0.x prior to 2.0.2 allows remote malicious users to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
5.5
CVSSv2
CVE-2011-4285
The default configuration of Moodle 2.0.x prior to 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
6.8
CVSSv2
CVE-2011-4287
admin/uploaduser_form.php in Moodle 2.0.x prior to 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote malicious users to obtain access by leveraging knowledge of the initial password of a new user.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4289
Moodle 2.0.x prior to 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4291
Moodle 2.0.x prior to 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4292
Moodle 2.0.x prior to 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
5.8
CVSSv2
CVE-2011-4294
The error-message functionality in Moodle 1.9.x prior to 1.9.13, 2.0.x prior to 2.0.4, and 2.1.x prior to 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow malicious users to trick users into visiting ar...
Moodle Moodle 2.0.2
Moodle Moodle 1.9.4
Moodle Moodle 1.9.1
Moodle Moodle 1.9.6
Moodle Moodle 1.9.9
Moodle Moodle 2.0.1
Moodle Moodle 1.9.11
Moodle Moodle 1.9.2
Moodle Moodle 1.9.12
Moodle Moodle 1.9.10
Moodle Moodle 2.0.3
Moodle Moodle 1.9.3
Moodle Moodle 1.9.5
Moodle Moodle 1.9.8
Moodle Moodle 1.9.7
Moodle Moodle 2.0.0
Moodle Moodle 2.1.0
6.5
CVSSv2
CVE-2011-4295
The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x prior to 2.0.4 and 2.1.x prior to 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.3
Moodle Moodle 2.0.0
Moodle Moodle 2.1.0
5.5
CVSSv2
CVE-2011-4296
lib/db/access.php in Moodle 2.0.x prior to 2.0.4 and 2.1.x prior to 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.3
Moodle Moodle 2.0.0
Moodle Moodle 2.1.0
6.4
CVSSv2
CVE-2011-4297
comment/lib.php in Moodle 2.0.x prior to 2.0.4 and 2.1.x prior to 2.1.1 does not properly restrict comment capabilities, which allows remote malicious users to post a comment by leveraging the guest role and operating on a front-page activity.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.3
Moodle Moodle 2.0.0
Moodle Moodle 2.1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
NEXT »