Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
BDU:2025-11660
Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить провести атаку межсайтового скриптинга (XSS)
GHSA-34g7-pg9j-pxgp
Moodle allows IDOR when accessing the cohorts report
GHSA-9vc3-vm42-fjhm
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
GHSA-6g5x-h5x7-q4mq
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
GHSA-pj96-xh2w-fgqx
Moodle has an IDOR in messaging web service which allows access to some user details
GHSA-cpm7-mv33-jwf8
Moodle's AJAX section delete does not respect course_can_delete_section()
GHSA-c8v6-vxhf-wcrr
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
GHSA-chmf-m33p-ph8m
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
GHSA-m8qh-hx4c-h9hr
Moodle has a CSRF risk in Brickfield tool's analysis request action
GHSA-88xj-97gf-7wpq
Moodle has a CSRF risk in user tours manager that allows tour duplication
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2025-11660 Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить провести атаку межсайтового скриптинга (XSS) | CVSS3: 5.7 | 0% Низкий | около 1 года назад | |
GHSA-34g7-pg9j-pxgp Moodle allows IDOR when accessing the cohorts report | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-9vc3-vm42-fjhm Moodle's mod_data edit/delete pages pass CSRF token in GET parameter | CVSS3: 3.1 | 0% Низкий | больше 1 года назад | |
GHSA-6g5x-h5x7-q4mq Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-pj96-xh2w-fgqx Moodle has an IDOR in messaging web service which allows access to some user details | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-cpm7-mv33-jwf8 Moodle's AJAX section delete does not respect course_can_delete_section() | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-c8v6-vxhf-wcrr Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-chmf-m33p-ph8m Moodle allows IDOR in RSS block, which allows access to additional RSS feeds | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-m8qh-hx4c-h9hr Moodle has a CSRF risk in Brickfield tool's analysis request action | 0% Низкий | больше 1 года назад | ||
GHSA-88xj-97gf-7wpq Moodle has a CSRF risk in user tours manager that allows tour duplication | CVSS3: 3.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу