Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

github логотип

GHSA-cgvv-3455-824j

3 месяца назад

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-53021

3 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2025-53021

3 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2025-53021

3 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2025-10235

3 месяца назад

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-m8qh-hx4c-h9hr

5 месяцев назад

Moodle has a CSRF risk in Brickfield tool's analysis request action

EPSS: Низкий
nvd логотип

CVE-2025-3638

5 месяцев назад

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-3638

5 месяцев назад

A flaw was found in Moodle. The analysis request action in the Brickfi ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2025-3638

5 месяцев назад

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-06871

5 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-cgvv-3455-824j

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-10235

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
0%
Низкий
3 месяца назад
github логотип
GHSA-m8qh-hx4c-h9hr

Moodle has a CSRF risk in Brickfield tool's analysis request action

0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-3638

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-3638

A flaw was found in Moodle. The analysis request action in the Brickfi ...

CVSS3: 8.8
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-3638

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-06871

Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться