Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-89f3-74m6-g27g

около 4 лет назад

Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module

EPSS: Низкий
github логотип

GHSA-wmmc-qjq2-vvm2

около 4 лет назад

Moodle is vulnerable to Sensitive Information Disclosure

EPSS: Низкий
github логотип

GHSA-x6xq-cgc6-h2fq

около 4 лет назад

mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.

EPSS: Низкий
github логотип

GHSA-prrh-679x-79qh

около 4 лет назад

Moodle allows remote authenticated users to reassign notes

EPSS: Низкий
github логотип

GHSA-664q-mrxx-2x2v

около 4 лет назад

Moodle does not properly manage privileges for WebDAV repositories

EPSS: Низкий
github логотип

GHSA-xr24-jp5c-6c4v

около 4 лет назад

Moodle reveals absolute path in exception message

EPSS: Низкий
github логотип

GHSA-pgp5-rcwp-qvfg

около 4 лет назад

Moodle includes the WebDAV password in the configuration form

EPSS: Низкий
github логотип

GHSA-8r7x-qq55-74v2

около 4 лет назад

Moodle does not enforce the forceloginforprofiles setting

EPSS: Низкий
github логотип

GHSA-fx5h-3786-h2w6

около 4 лет назад

PHP Spellchecker addon for TinyMCE allows attackers to trigger arbitrary outbound HTTP requests

EPSS: Низкий
github логотип

GHSA-p239-x7hg-j3w6

около 4 лет назад

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-89f3-74m6-g27g

Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module

1%
Низкий
около 4 лет назад
github логотип
GHSA-wmmc-qjq2-vvm2

Moodle is vulnerable to Sensitive Information Disclosure

2%
Низкий
около 4 лет назад
github логотип
GHSA-x6xq-cgc6-h2fq

mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.

1%
Низкий
около 4 лет назад
github логотип
GHSA-prrh-679x-79qh

Moodle allows remote authenticated users to reassign notes

2%
Низкий
около 4 лет назад
github логотип
GHSA-664q-mrxx-2x2v

Moodle does not properly manage privileges for WebDAV repositories

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr24-jp5c-6c4v

Moodle reveals absolute path in exception message

1%
Низкий
около 4 лет назад
github логотип
GHSA-pgp5-rcwp-qvfg

Moodle includes the WebDAV password in the configuration form

1%
Низкий
около 4 лет назад
github логотип
GHSA-8r7x-qq55-74v2

Moodle does not enforce the forceloginforprofiles setting

2%
Низкий
около 4 лет назад
github логотип
GHSA-fx5h-3786-h2w6

PHP Spellchecker addon for TinyMCE allows attackers to trigger arbitrary outbound HTTP requests

2%
Низкий
около 4 лет назад
github логотип
GHSA-p239-x7hg-j3w6

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться