Where
AND
AND
-Infinity
0
Severity
6.8
Path Traversal
AV:N/AC:L/Au:S/C:C/I:N/A:N

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

First published (updated )
Severity
4.6
Code Injection
AV:N/AC:H/Au:S/C:P/I:P/A:P

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.

1 / 2
Source: GitHub
First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

notes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated users to reassign notes via a modified (1) userid or (2) courseid field.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

grade/edit/outcome/editform.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

First published (updated )
Severity
6.5
SQL Injection
AV:N/AC:L/Au:S/C:P/I:P/A:P

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

The ipinrange function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/actionredir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

login/changepassword.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

First published (updated )
Severity
5
CRLF Injection
AV:N/AC:L/Au:N/C:N/I:P/A:N

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

First published (updated )
Severity
6.5
Input Validation
AV:N/AC:L/Au:S/C:P/I:P/A:P

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

First published (updated )
Severity
4
Code Injection
AV:N/AC:L/Au:S/C:N/I:P/A:N

Impact Arbitrary additional email headers can be injected via crafted From or Sender headers.

Patches Fixed in 2.2.1

Workarounds Filter user-supplied values prior to using them in From or Sender properties.

References https://nvd.nist.gov/vuln/detail/CVE-2012-0796

For more information If you have any questions or comments about this advisory: Open a private issue in the PHPMailer project

1 / 2
First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

First published (updated )
Severity
5.8
Input Validation
AV:N/AC:M/Au:N/C:N/I:P/A:P

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.

1 / 2
Source: GitHub
First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

First published (updated )
Severity
6.8
CSRF
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:N/A:P

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:P/I:N/A:N

mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.

1 / 2
Source: GitHub
First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

A number of flaws have been fixed in new upstream Moodle 2.2.1 [1], 2.1.4 [2], 2.0.7 [3], and 1.9.16 [4] releases. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating a number of separate bugs.

[1] http://docs.moodle.org/dev/Moodle2.2.1releasenotes [2] http://docs.moodle.org/dev/Moodle2.1.4releasenotes [3] http://docs.moodle.org/dev/Moodle2.0.7releasenotes [4] http://docs.moodle.org/dev/Moodle1.9.16releasenotes

MSA-12-0001: Recaptcha transmission consistency issue Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=b608b227bac4efba76da43dabe9bc2e32fb8fa32 Reference: http://moodle.org/mod/forum/discuss.php?d=194008

MSA-12-0002: Personal information leak Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=36b0ddeed45d0751508dcd9fa50f17fda43bae54 Reference: http://moodle.org/mod/forum/discuss.php?d=194009

MSA-12-0003: Added password protection Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=aa30d3e8ce0dd41d3d0f7dae856beb180fed1f83 Reference: http://moodle.org/mod/forum/discuss.php?d=194011

MSA-12-0004: Added profile image security Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=90911c4ff98dc2078a3acef5ddf5a1a8f7e20ba5 Reference: http://moodle.org/mod/forum/discuss.php?d=194012

MSA-12-0005: Encryption enhancement Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=98456628a24bba25d336860d38a45b5a4e3895da Reference: http://moodle.org/mod/forum/discuss.php?d=194013

MSA-12-0006: Additional email address validation Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-13572 Reference: http://moodle.org/mod/forum/discuss.php?d=194014

MSA-12-0007: Email injection prevention Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=62988bf0bbc73df655f51884aaf1f523928abff9 Reference: http://moodle.org/mod/forum/discuss.php?d=194015

MSA-12-0008: Unsynchronised access via tokens Affects: 2.2, 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28126 Reference: http://moodle.org/mod/forum/discuss.php?d=194016

MSA-12-0009: Role access issue Affects: 2.2, 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29469 Reference: http://moodle.org/mod/forum/discuss.php?d=194017

MSA-12-0010: Unauthorised access to session key Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-27334 Reference: http://moodle.org/mod/forum/discuss.php?d=194018

MSA-12-0011: Browser autofill password issue Affects: 2.2, 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=6e9989dbd3f261b2e1586ff77b0bf22fc7091485 Reference: http://moodle.org/mod/forum/discuss.php?d=194019

MSA-12-0012: Form validation issue Affects: 2.2, 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=51070abc78b9e1db1db9a44855e8623b22bebd48 Reference: http://moodle.org/mod/forum/discuss.php?d=194020

1 / 2
Source: Red Hat
First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203