Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

github логотип

GHSA-45rw-4r25-jvg7

больше 3 лет назад

Moodle Logged in users could view all calendar events

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qrcj-6fjw-3h9h

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-wm4w-8vc6-2j4h

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8wf8-rc66-c638

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

EPSS: Низкий
github логотип

GHSA-7w7p-v23v-56qr

почти 4 года назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

EPSS: Низкий
github логотип

GHSA-rj5x-jhhc-5x6h

почти 4 года назад

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

EPSS: Низкий
github логотип

GHSA-6w97-x9wf-g8mv

почти 4 года назад

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

EPSS: Низкий
github логотип

GHSA-79vx-7whj-rvvr

почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-gmx9-p92v-48wf

почти 4 года назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

EPSS: Низкий
github логотип

GHSA-4452-2568-9wpm

почти 4 года назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-45rw-4r25-jvg7

Moodle Logged in users could view all calendar events

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-qrcj-6fjw-3h9h

Moodle XSS Vulnerability

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wm4w-8vc6-2j4h

Moodle XSS Vulnerability

CVSS3: 5.3
4%
Низкий
больше 3 лет назад
github логотип
GHSA-8wf8-rc66-c638

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

8%
Низкий
почти 4 года назад
github логотип
GHSA-7w7p-v23v-56qr

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

1%
Низкий
почти 4 года назад
github логотип
GHSA-rj5x-jhhc-5x6h

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-6w97-x9wf-g8mv

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

1%
Низкий
почти 4 года назад
github логотип
GHSA-79vx-7whj-rvvr

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-gmx9-p92v-48wf

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

1%
Низкий
почти 4 года назад
github логотип
GHSA-4452-2568-9wpm

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться