Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 577
GHSA-wxqg-fg7v-mmc6
Moodle Authenticated Spelling Binary Remote Code Execution
GHSA-45rw-4r25-jvg7
Moodle Logged in users could view all calendar events
GHSA-qrcj-6fjw-3h9h
Moodle XSS Vulnerability
GHSA-wm4w-8vc6-2j4h
Moodle XSS Vulnerability
GHSA-8wf8-rc66-c638
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.
GHSA-7w7p-v23v-56qr
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
GHSA-rj5x-jhhc-5x6h
mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.
GHSA-79vx-7whj-rvvr
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
GHSA-6w97-x9wf-g8mv
login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.
GHSA-gmx9-p92v-48wf
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-wxqg-fg7v-mmc6 Moodle Authenticated Spelling Binary Remote Code Execution | 65% Средний | больше 3 лет назад | ||
GHSA-45rw-4r25-jvg7 Moodle Logged in users could view all calendar events | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-qrcj-6fjw-3h9h Moodle XSS Vulnerability | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад | |
GHSA-wm4w-8vc6-2j4h Moodle XSS Vulnerability | CVSS3: 5.3 | 8% Низкий | больше 3 лет назад | |
GHSA-8wf8-rc66-c638 Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed. | 13% Средний | больше 3 лет назад | ||
GHSA-7w7p-v23v-56qr SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)." | 1% Низкий | больше 3 лет назад | ||
GHSA-rj5x-jhhc-5x6h mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-79vx-7whj-rvvr Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-6w97-x9wf-g8mv login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing. | 1% Низкий | больше 3 лет назад | ||
GHSA-gmx9-p92v-48wf Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу