Loading...
Loading...
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
June 1, 2015
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2015-0211
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.