Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-f9m9-494r-w36p

около 4 лет назад

Moodle allows bypass of intended access restrictions

EPSS: Низкий
github логотип

GHSA-j465-7mp6-3xg3

около 4 лет назад

Moodle places a session key in a URL

EPSS: Низкий
github логотип

GHSA-h2rg-p9qr-pqcr

около 4 лет назад

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

EPSS: Низкий
github логотип

GHSA-m2f7-57gp-v34q

около 4 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

EPSS: Низкий
github логотип

GHSA-w2pj-r8m3-r4jc

около 4 лет назад

Moodle Information Disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mmvj-j7hq-rx85

около 4 лет назад

Moodle sensitive information disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xfgq-37vh-892j

около 4 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-j6c3-3c4w-qv8p

около 4 лет назад

Moodle cross-site scripting (XSS) vulnerabilities

EPSS: Низкий
github логотип

GHSA-c2r4-f8qv-2v7v

около 4 лет назад

Moodle allows attackers to read SCORM contents

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g4wf-f588-7xc7

около 4 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-f9m9-494r-w36p

Moodle allows bypass of intended access restrictions

1%
Низкий
около 4 лет назад
github логотип
GHSA-j465-7mp6-3xg3

Moodle places a session key in a URL

2%
Низкий
около 4 лет назад
github логотип
GHSA-h2rg-p9qr-pqcr

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

1%
Низкий
около 4 лет назад
github логотип
GHSA-m2f7-57gp-v34q

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w2pj-r8m3-r4jc

Moodle Information Disclosure

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-mmvj-j7hq-rx85

Moodle sensitive information disclosure

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xfgq-37vh-892j

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-j6c3-3c4w-qv8p

Moodle cross-site scripting (XSS) vulnerabilities

2%
Низкий
около 4 лет назад
github логотип
GHSA-c2r4-f8qv-2v7v

Moodle allows attackers to read SCORM contents

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-g4wf-f588-7xc7

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться