Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

nvd логотип

CVE-2024-43437

12 месяцев назад

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-43437

12 месяцев назад

A flaw was found in moodle. Insufficient sanitizing of data when perfo ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-43435

12 месяцев назад

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43435

12 месяцев назад

A flaw was found in moodle. Insufficient capability checks make it pos ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-43433

12 месяцев назад

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43433

12 месяцев назад

A flaw was found in moodle. Matrix room membership and power levels ar ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-43432

12 месяцев назад

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43432

12 месяцев назад

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-43430

12 месяцев назад

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43430

12 месяцев назад

A flaw was found in moodle. External API access to Quiz can override c ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
1%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when perfo ...

CVSS3: 5.4
1%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
1%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it pos ...

CVSS3: 5.3
1%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels ar ...

CVSS3: 5.3
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-43432

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43432

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH ...

CVSS3: 5.3
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-43430

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43430

A flaw was found in moodle. External API access to Quiz can override c ...

CVSS3: 5.3
0%
Низкий
12 месяцев назад

Уязвимостей на страницу


Поделиться