Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 536
GHSA-cgvv-3455-824j
Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

BDU:2025-10235
Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя
GHSA-m8qh-hx4c-h9hr
Moodle has a CSRF risk in Brickfield tool's analysis request action

CVE-2025-3638
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
CVE-2025-3638
A flaw was found in Moodle. The analysis request action in the Brickfi ...

CVE-2025-3638
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

BDU:2025-06871
Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-cgvv-3455-824j Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
![]() | CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 3 месяца назад |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ... | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
![]() | CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 3 месяца назад |
![]() | BDU:2025-10235 Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя | CVSS3: 4.2 | 0% Низкий | 3 месяца назад |
GHSA-m8qh-hx4c-h9hr Moodle has a CSRF risk in Brickfield tool's analysis request action | 0% Низкий | 5 месяцев назад | ||
![]() | CVE-2025-3638 A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад |
CVE-2025-3638 A flaw was found in Moodle. The analysis request action in the Brickfi ... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
![]() | CVE-2025-3638 A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад |
![]() | BDU:2025-06871 Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу