Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-389j-qw4x-m76h

больше 3 лет назад

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

EPSS: Низкий
github логотип

GHSA-5xqf-3mwv-q7gm

больше 3 лет назад

Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-6q9g-3vfq-q2qj

больше 3 лет назад

Improper Authentication in moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c5hf-mc85-2hx4

больше 3 лет назад

Missing authorization in Moodle

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0984

больше 3 лет назад

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0984

больше 3 лет назад

Users with the capability to configure badge criteria (teachers and ma ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0984

больше 3 лет назад

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0985

больше 3 лет назад

Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0985

больше 3 лет назад

Insufficient capability checks could allow users with the moodle/site: ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0985

больше 3 лет назад

Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-389j-qw4x-m76h

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-5xqf-3mwv-q7gm

Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6q9g-3vfq-q2qj

Improper Authentication in moodle

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c5hf-mc85-2hx4

Missing authorization in Moodle

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-0984

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-0984

Users with the capability to configure badge criteria (teachers and ma ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-0984

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-0985

Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-0985

Insufficient capability checks could allow users with the moodle/site: ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-0985

Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться