NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37973 | CVE-2013-1830 | user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search. | 2 | 5 | Medium | 2017-01-18 | 2016-10-03 | View | |
13137 | CVE-2010-1617 | user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page. | 2 | 4 | Medium | 2017-01-18 | 2010-05-22 | View | |
46592 | CVE-2012-5454 | user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168. | 2 | 6.5 | Medium | 2017-01-19 | 2013-04-10 | View | |
48939 | CVE-2009-1670 | user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-06-09 | View | |
18426 | CVE-2016-2151 | user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list. | 2 | 4 | Medium | 2017-01-19 | 2016-05-24 | View |
Page 667 of 17672, showing 5 records out of 88360 total, starting on record 3331, ending on 3335