Where
AND
AND
-Infinity
0
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

First published (updated )
Severity
6.4
AV:N/AC:L/Au:N/C:N/I:P/A:P

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

admin/uploaduserform.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

First published (updated )
Severity
4
Input Validation
AV:N/AC:L/Au:S/C:N/I:N/A:P

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

First published (updated )
Severity
4
SQL Injection
AV:N/AC:L/Au:S/C:N/I:N/A:P

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

First published (updated )
Severity
6.8
CSRF
AV:N/AC:M/Au:N/C:P/I:P/A:P

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/actionredir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

A number of flaws have been fixed in new upstream Moodle 2.1.3 [1], 2.0.6 [2], and 1.9.15 [3] releases. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating a number of separate bugs.

[1] http://docs.moodle.org/dev/Moodle2.1.3releasenotes [2] http://docs.moodle.org/dev/Moodle2.0.6releasenotes [3] http://docs.moodle.org/dev/Moodle1.9.15releasenotes

MSA-11-0042: Information leak in Wiki Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=140af2a0f0a4598bf568b9ae182cb81eb583edeb Reference: http://moodle.org/mod/forum/discuss.php?d=191747

MSA-11-0043: Possible link redirect in Calendar Affects: 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28720&sr=1 Reference: http://moodle.org/mod/forum/discuss.php?d=191748

MSA-11-0044: Expired identification information shown in Web services Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28670&sr=1 Reference: http://moodle.org/mod/forum/discuss.php?d=191750

MSA-11-0045: Potential to masquerade through MNet Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=10df8657c1c138c0d0ab1d4796c552fcec0c299b Reference: http://moodle.org/mod/forum/discuss.php?d=191751

MSA-11-0046: Insecure authentication transmission Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=01dd64a8c8aa95f793accea371b2392e662663c5 Reference: http://moodle.org/mod/forum/discuss.php?d=191752

MSA-11-0047: Possible injection attack in Calendar Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=581e8dba387f090d89382115fd850d8b44351526 Reference: moodle.org/mod/forum/discuss.php?d=191754

MSA-11-0048: Password loss issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=e079e82c087becf06d902089d14f3f76686bde19 Reference: http://moodle.org/mod/forum/discuss.php?d=191755

MSA-11-0049: Network restriction ineffective with MNet Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=3ab2851d2a59721445945d0706c58092e07e861e Reference: http://moodle.org/mod/forum/discuss.php?d=191756

MSA-11-0050: Backup capability issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29591 Reference: http://moodle.org/mod/forum/discuss.php?d=191758

MSA-11-0051: Authentication issue with Web services Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28629 Reference: http://moodle.org/mod/forum/discuss.php?d=191759

MSA-11-0052: Potential to exploit developer debugging scripts Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=187672608ec96659e07f2461b3b83634debd16cb Reference: http://moodle.org/mod/forum/discuss.php?d=191760

MSA-11-0053: Security and system administration conflict Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=ade30ad3c420ce035a3d68287db701b70e806b3f Refrence: http://moodle.org/mod/forum/discuss.php?d=191761

MSA-11-0054: Personal information leak Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=e94113a859015a4a80b9397957b8fc4044e2951f Reference: http://moodle.org/mod/forum/discuss.php?d=191762

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:N/I:P/A:P

backup/moodle2/restorestepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

First published (updated )
Severity
5
CRLF Injection
AV:N/AC:L/Au:N/C:N/I:P/A:N

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:P/A:N

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in the printobject function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:P/I:N/A:N

mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

1 / 2
Source: GitHub
First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

First published (updated )
Severity
4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registrationhubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:P/I:N/A:N

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

First published (updated )
Severity
5.8
Input Validation
AV:N/AC:M/Au:N/C:N/I:P/A:P

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.

1 / 2
Source: GitHub
First published (updated )
Severity
4
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

The moodleenrolexternal:roleassign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

First published (updated )
Severity
6.8
Input Validation
AV:N/AC:M/Au:N/C:P/I:P/A:P

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the opensslverify function, which allows remote attackers to bypass validation via a crafted certificate.

First published (updated )
Severity
6.4
AV:N/AC:L/Au:N/C:N/I:P/A:P

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:N/I:P/A:P

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203