Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  >> 3.2.0  Security Vulnerabilities
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
CVSS Score
6.3
EPSS Score
0.003
Published
2017-05-15
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
CVSS Score
5.3
EPSS Score
0.003
Published
2017-05-15
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVSS Score
4.3
EPSS Score
0.001
Published
2017-05-15
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVSS Score
9.8
EPSS Score
0.019
Published
2017-03-26
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVSS Score
5.3
EPSS Score
0.008
Published
2017-03-26
In Moodle 3.x, XSS can occur via evidence of prior learning.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-03-26
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-03-26
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
CVSS Score
5.3
EPSS Score
0.003
Published
2017-01-20
In Moodle 3.x, there is XSS in the assignment submission page.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-01-20
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.
CVSS Score
4.3
EPSS Score
0.029
Published
2010-11-07


Contact Us

Shodan ® - All rights reserved