Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-9r38-f9p6-3f7p

около 4 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS: Низкий
github логотип

GHSA-6ggr-h9vf-pg47

около 4 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

EPSS: Низкий
github логотип

GHSA-3f43-8vw5-xcf9

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

EPSS: Низкий
github логотип

GHSA-75c6-xqwr-v2r9

около 4 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-pg89-qp74-vch2

около 4 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

EPSS: Низкий
github логотип

GHSA-ch68-5r37-p7c3

около 4 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-h46g-v2m5-f7jh

около 4 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

EPSS: Низкий
github логотип

GHSA-6p3g-hw27-qh44

около 4 лет назад

Moodle's time-validation implementation allows bypassing intended restrictions

EPSS: Низкий
github логотип

GHSA-267j-cwvg-j28c

около 4 лет назад

Moodle attackers to modify grade metadata

EPSS: Низкий
github логотип

GHSA-4wvg-7886-83gv

около 4 лет назад

Moodle cross-site request forgery (CSRF) vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9r38-f9p6-3f7p

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6ggr-h9vf-pg47

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3f43-8vw5-xcf9

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-75c6-xqwr-v2r9

Moodle cross-site scripting (XSS) vulnerability

1%
Низкий
около 4 лет назад
github логотип
GHSA-pg89-qp74-vch2

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

1%
Низкий
около 4 лет назад
github логотип
GHSA-ch68-5r37-p7c3

Moodle cross-site scripting (XSS) vulnerability

2%
Низкий
около 4 лет назад
github логотип
GHSA-h46g-v2m5-f7jh

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6p3g-hw27-qh44

Moodle's time-validation implementation allows bypassing intended restrictions

2%
Низкий
около 4 лет назад
github логотип
GHSA-267j-cwvg-j28c

Moodle attackers to modify grade metadata

1%
Низкий
около 4 лет назад
github логотип
GHSA-4wvg-7886-83gv

Moodle cross-site request forgery (CSRF) vulnerability

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться