Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
CVE-2024-43437
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
CVE-2024-43437
A flaw was found in moodle. Insufficient sanitizing of data when perfo ...
CVE-2024-43435
A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.
CVE-2024-43435
A flaw was found in moodle. Insufficient capability checks make it pos ...
CVE-2024-43433
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
CVE-2024-43433
A flaw was found in moodle. Matrix room membership and power levels ar ...
CVE-2024-43432
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
CVE-2024-43432
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH ...
CVE-2024-43430
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
CVE-2024-43430
A flaw was found in moodle. External API access to Quiz can override c ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-43437 A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. | CVSS3: 5.4 | 1% Низкий | 12 месяцев назад | |
CVE-2024-43437 A flaw was found in moodle. Insufficient sanitizing of data when perfo ... | CVSS3: 5.4 | 1% Низкий | 12 месяцев назад | |
CVE-2024-43435 A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary. | CVSS3: 5.3 | 1% Низкий | 12 месяцев назад | |
CVE-2024-43435 A flaw was found in moodle. Insufficient capability checks make it pos ... | CVSS3: 5.3 | 1% Низкий | 12 месяцев назад | |
CVE-2024-43433 A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-43433 A flaw was found in moodle. Matrix room membership and power levels ar ... | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-43432 A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-43432 A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH ... | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-43430 A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2024-43430 A flaw was found in moodle. External API access to Quiz can override c ... | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад |
Уязвимостей на страницу