Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-3w4p-mc7m-x3qf

около 4 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

EPSS: Низкий
github логотип

GHSA-cr78-rphw-w73p

около 4 лет назад

Moodle Arbitrary File Read via Backup Functionality

EPSS: Низкий
github логотип

GHSA-2hw8-qj3h-c7pq

около 4 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

EPSS: Низкий
github логотип

GHSA-cxp8-jjf5-6whc

около 4 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

EPSS: Низкий
github логотип

GHSA-782m-5wvg-q53x

около 4 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

EPSS: Низкий
github логотип

GHSA-vm9c-39jx-q45w

около 4 лет назад

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

EPSS: Низкий
github логотип

GHSA-x5hj-47vv-53p8

около 4 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-475h-wv64-r896

около 4 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

EPSS: Низкий
github логотип

GHSA-64r3-582j-frqm

около 4 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-gxf9-5xr3-34cc

около 4 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-3w4p-mc7m-x3qf

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cr78-rphw-w73p

Moodle Arbitrary File Read via Backup Functionality

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hw8-qj3h-c7pq

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cxp8-jjf5-6whc

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

1%
Низкий
около 4 лет назад
github логотип
GHSA-782m-5wvg-q53x

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

1%
Низкий
около 4 лет назад
github логотип
GHSA-vm9c-39jx-q45w

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

2%
Низкий
около 4 лет назад
github логотип
GHSA-x5hj-47vv-53p8

YUI Cross-site Scripting (XSS) vulnerability

1%
Низкий
около 4 лет назад
github логотип
GHSA-475h-wv64-r896

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

1%
Низкий
около 4 лет назад
github логотип
GHSA-64r3-582j-frqm

YUI Cross-site Scripting (XSS) vulnerability

1%
Низкий
около 4 лет назад
github логотип
GHSA-gxf9-5xr3-34cc

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться