Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 577
GHSA-fmfx-pgpf-66r5
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
GHSA-853r-xfvj-j429
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
GHSA-2c5m-jj29-px47
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.
GHSA-hj48-8q8c-q7g9
Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
GHSA-3vcq-64gh-84x2
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
GHSA-79h5-2hp9-w4p4
Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
GHSA-q34m-x5mm-6rwc
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.
BDU:2022-03182
Уязвимость реализации класса core_auth виртуальной обучающей среды Moodle, позволяющая нарушителю обойти ограничения безопасности
GHSA-j98x-965h-9v2h
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
GHSA-wwrq-jww7-39jq
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-fmfx-pgpf-66r5 Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. | 0% Низкий | больше 3 лет назад | ||
GHSA-853r-xfvj-j429 SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements. | 1% Низкий | больше 3 лет назад | ||
GHSA-2c5m-jj29-px47 Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter. | 4% Низкий | больше 3 лет назад | ||
GHSA-hj48-8q8c-q7g9 Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3vcq-64gh-84x2 Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-79h5-2hp9-w4p4 Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-q34m-x5mm-6rwc Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter. | 2% Низкий | больше 3 лет назад | ||
BDU:2022-03182 Уязвимость реализации класса core_auth виртуальной обучающей среды Moodle, позволяющая нарушителю обойти ограничения безопасности | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
GHSA-j98x-965h-9v2h Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough | 0% Низкий | больше 3 лет назад | ||
GHSA-wwrq-jww7-39jq Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу