|
267781
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated u…
|
CWE-284
Improper Access Control
|
CVE-2016-2159
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267782
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attacke…
|
CWE-200
Information Exposure
|
CVE-2016-2158
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267783
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 all…
|
CWE-352
Origin Validation Error
|
CVE-2016-2157
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267784
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an act…
|
CWE-200
Information Exposure
|
CVE-2016-2156
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267785
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allow…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2155
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267786
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows re…
|
CWE-200
Information Exposure
|
CVE-2016-2154
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267787
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allo…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2153
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267788
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2152
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267789
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhidd…
|
CWE-200
Information Exposure
|
CVE-2016-2151
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267790
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permissi…
|
CWE-284
Improper Access Control
|
CVE-2016-2100
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|