NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
37973  CVE-2013-1830  user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.    Medium  2017-01-18  2016-10-03  View
13137  CVE-2010-1617  user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.    Medium  2017-01-18  2010-05-22  View
46592  CVE-2012-5454  user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.    6.5  Medium  2017-01-19  2013-04-10  View
48939  CVE-2009-1670  user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2009-06-09  View
18426  CVE-2016-2151  user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.    Medium  2017-01-19  2016-05-24  View

Page 667 of 17672, showing 5 records out of 88360 total, starting on record 3331, ending on 3335

Actions