CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61777  CVE-2013-1830  Candidate  user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.  Assigned (20130219)  None (candidate not yet proposed)    View
44201  CVE-2010-1617  Candidate  user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.  Assigned (20100429)  None (candidate not yet proposed)    View
58697  CVE-2012-5454  Candidate  user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.  Assigned (20121022)  None (candidate not yet proposed)    View
39105  CVE-2009-1670  Candidate  user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.  Assigned (20090518)  None (candidate not yet proposed)    View
88970  CVE-2016-2151  Candidate  user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.  Assigned (20160129)  None (candidate not yet proposed)    View

Page 589 of 20943, showing 5 records out of 104715 total, starting on record 2941, ending on 2945

Actions