Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-4pv6-rw85-g6wg

около 4 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

EPSS: Низкий
github логотип

GHSA-g632-g52c-3j8c

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

EPSS: Низкий
github логотип

GHSA-gr8w-hm62-xw58

около 4 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

EPSS: Низкий
github логотип

GHSA-w66h-c2vj-cm7f

около 4 лет назад

Moodle Authentication Bypass in File Upload

EPSS: Низкий
github логотип

GHSA-wp3g-pr4h-q6vv

около 4 лет назад

Moodle does not enforce capability requirements for reading blog comments

EPSS: Низкий
github логотип

GHSA-893p-hqf6-mg67

около 4 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

EPSS: Низкий
github логотип

GHSA-x3x8-fjw6-hccx

около 4 лет назад

Moodle does not consider "don't send" attributes during hub registration

EPSS: Низкий
github логотип

GHSA-cc94-hwj3-rf65

около 4 лет назад

Moodle's login_as feature leaks information from external repositories

EPSS: Низкий
github логотип

GHSA-mxp2-wcjh-jf72

около 4 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

EPSS: Низкий
github логотип

GHSA-m63h-q4x3-6hwj

около 4 лет назад

Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-4pv6-rw85-g6wg

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g632-g52c-3j8c

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-gr8w-hm62-xw58

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w66h-c2vj-cm7f

Moodle Authentication Bypass in File Upload

1%
Низкий
около 4 лет назад
github логотип
GHSA-wp3g-pr4h-q6vv

Moodle does not enforce capability requirements for reading blog comments

2%
Низкий
около 4 лет назад
github логотип
GHSA-893p-hqf6-mg67

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x3x8-fjw6-hccx

Moodle does not consider "don't send" attributes during hub registration

2%
Низкий
около 4 лет назад
github логотип
GHSA-cc94-hwj3-rf65

Moodle's login_as feature leaks information from external repositories

1%
Низкий
около 4 лет назад
github логотип
GHSA-mxp2-wcjh-jf72

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m63h-q4x3-6hwj

Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class

2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться