Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-qqvp-r28f-c3cv
lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.
GHSA-2jcw-r79x-4r5v
Moodle does not set the RISK_XSS bit for graders
GHSA-m7cc-6vhg-39wr
Moodle improper access control
GHSA-ghqg-3wq5-437q
Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.
GHSA-v33x-q8gh-4x42
Moodle multiple cross-site request forgery (CSRF) vulnerabilities
GHSA-2hw6-6rgf-726v
Moodle XSS Vulnerability
GHSA-44xp-wj24-9xxj
Moodle allows attackers to delete files
GHSA-f7qm-q26p-6rr2
Moodle cross-site scripting (XSS) vulnerability
GHSA-5729-822w-j342
Moodle cross-site scripting (XSS) vulnerability
GHSA-382v-gxj9-ffhc
Moodle uses predictable password-recovery tokens
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-qqvp-r28f-c3cv lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report. | 2% Низкий | около 4 лет назад | ||
GHSA-2jcw-r79x-4r5v Moodle does not set the RISK_XSS bit for graders | 1% Низкий | около 4 лет назад | ||
GHSA-m7cc-6vhg-39wr Moodle improper access control | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-ghqg-3wq5-437q Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields. | 1% Низкий | около 4 лет назад | ||
GHSA-v33x-q8gh-4x42 Moodle multiple cross-site request forgery (CSRF) vulnerabilities | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-2hw6-6rgf-726v Moodle XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-44xp-wj24-9xxj Moodle allows attackers to delete files | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-f7qm-q26p-6rr2 Moodle cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-5729-822w-j342 Moodle cross-site scripting (XSS) vulnerability | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-382v-gxj9-ffhc Moodle uses predictable password-recovery tokens | CVSS3: 7.5 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу