Vulnerabilities
Vulnerable Software
Moodle:  Security Vulnerabilities
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
CVSS Score
4.3
EPSS Score
0.012
Published
2019-11-14
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
CVSS Score
4.3
EPSS Score
0.014
Published
2019-11-14
Moodle before 2.2.2: Overview report allows users to see hidden courses
CVSS Score
4.3
EPSS Score
0.014
Published
2019-11-14
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
CVSS Score
2.7
EPSS Score
0.012
Published
2019-11-14
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
CVSS Score
4.3
EPSS Score
0.014
Published
2019-11-14
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
CVSS Score
5.3
EPSS Score
0.018
Published
2019-11-14
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVSS Score
7.5
EPSS Score
0.021
Published
2019-11-14
Moodle before 2.2.2 has users' private files included in course backups
CVSS Score
7.5
EPSS Score
0.021
Published
2019-11-14
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVSS Score
8.2
EPSS Score
0.023
Published
2019-11-14
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
CVSS Score
6.5
EPSS Score
0.011
Published
2019-07-31


Contact Us

Shodan ® - All rights reserved