Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-9r38-f9p6-3f7p
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
GHSA-6ggr-h9vf-pg47
mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.
GHSA-3f43-8vw5-xcf9
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
GHSA-75c6-xqwr-v2r9
Moodle cross-site scripting (XSS) vulnerability
GHSA-pg89-qp74-vch2
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.
GHSA-ch68-5r37-p7c3
Moodle cross-site scripting (XSS) vulnerability
GHSA-h46g-v2m5-f7jh
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
GHSA-6p3g-hw27-qh44
Moodle's time-validation implementation allows bypassing intended restrictions
GHSA-267j-cwvg-j28c
Moodle attackers to modify grade metadata
GHSA-4wvg-7886-83gv
Moodle cross-site request forgery (CSRF) vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-9r38-f9p6-3f7p rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed. | 1% Низкий | около 4 лет назад | ||
GHSA-6ggr-h9vf-pg47 mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time. | 1% Низкий | около 4 лет назад | ||
GHSA-3f43-8vw5-xcf9 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | 1% Низкий | около 4 лет назад | ||
GHSA-75c6-xqwr-v2r9 Moodle cross-site scripting (XSS) vulnerability | 1% Низкий | около 4 лет назад | ||
GHSA-pg89-qp74-vch2 mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server. | 1% Низкий | около 4 лет назад | ||
GHSA-ch68-5r37-p7c3 Moodle cross-site scripting (XSS) vulnerability | 2% Низкий | около 4 лет назад | ||
GHSA-h46g-v2m5-f7jh mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document. | 1% Низкий | около 4 лет назад | ||
GHSA-6p3g-hw27-qh44 Moodle's time-validation implementation allows bypassing intended restrictions | 2% Низкий | около 4 лет назад | ||
GHSA-267j-cwvg-j28c Moodle attackers to modify grade metadata | 1% Низкий | около 4 лет назад | ||
GHSA-4wvg-7886-83gv Moodle cross-site request forgery (CSRF) vulnerability | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу