Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-f9m9-494r-w36p
Moodle allows bypass of intended access restrictions
GHSA-j465-7mp6-3xg3
Moodle places a session key in a URL
GHSA-h2rg-p9qr-pqcr
course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.
GHSA-m2f7-57gp-v34q
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
GHSA-w2pj-r8m3-r4jc
Moodle Information Disclosure
GHSA-mmvj-j7hq-rx85
Moodle sensitive information disclosure
GHSA-xfgq-37vh-892j
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
GHSA-j6c3-3c4w-qv8p
Moodle cross-site scripting (XSS) vulnerabilities
GHSA-c2r4-f8qv-2v7v
Moodle allows attackers to read SCORM contents
GHSA-g4wf-f588-7xc7
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-f9m9-494r-w36p Moodle allows bypass of intended access restrictions | 1% Низкий | около 4 лет назад | ||
GHSA-j465-7mp6-3xg3 Moodle places a session key in a URL | 2% Низкий | около 4 лет назад | ||
GHSA-h2rg-p9qr-pqcr course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request. | 1% Низкий | около 4 лет назад | ||
GHSA-m2f7-57gp-v34q Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request. | 1% Низкий | около 4 лет назад | ||
GHSA-w2pj-r8m3-r4jc Moodle Information Disclosure | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-mmvj-j7hq-rx85 Moodle sensitive information disclosure | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-xfgq-37vh-892j Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | CVSS3: 6.8 | 2% Низкий | около 4 лет назад | |
GHSA-j6c3-3c4w-qv8p Moodle cross-site scripting (XSS) vulnerabilities | 2% Низкий | около 4 лет назад | ||
GHSA-c2r4-f8qv-2v7v Moodle allows attackers to read SCORM contents | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-g4wf-f588-7xc7 mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization. | CVSS3: 4.3 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу