Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  >> 3.2.0  Security Vulnerabilities
In Moodle 3.x, course creators are able to change system default settings for courses.
CVSS Score
6.5
EPSS Score
0.009
Published
2017-07-17
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
CVSS Score
6.3
EPSS Score
0.012
Published
2017-05-15
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
CVSS Score
5.3
EPSS Score
0.01
Published
2017-05-15
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVSS Score
4.3
EPSS Score
0.005
Published
2017-05-15
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVSS Score
9.8
EPSS Score
0.145
Published
2017-03-26
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVSS Score
5.3
EPSS Score
0.016
Published
2017-03-26
In Moodle 3.x, XSS can occur via evidence of prior learning.
CVSS Score
6.1
EPSS Score
0.011
Published
2017-03-26
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVSS Score
6.1
EPSS Score
0.011
Published
2017-03-26
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
CVSS Score
5.3
EPSS Score
0.01
Published
2017-01-20
In Moodle 3.x, there is XSS in the assignment submission page.
CVSS Score
6.1
EPSS Score
0.009
Published
2017-01-20


Contact Us

Shodan ® - All rights reserved