Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

fstec логотип

BDU:2021-01194

больше 4 лет назад

Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной очисткой введенных пользователем данных в определенных поисковых запросах, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2020-25627

почти 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25627

почти 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to p ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25627

почти 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25631

почти 5 лет назад

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25631

почти 5 лет назад

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25630

почти 5 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25630

почти 5 лет назад

A vulnerability was found in Moodle where the decompressed size of zip ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-25629

почти 5 лет назад

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-25629

почти 5 лет назад

A vulnerability was found in Moodle where users with "Log in as" capab ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2021-01194

Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной очисткой введенных пользователем данных в определенных поисковых запросах, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
3%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to p ...

CVSS3: 6.1
3%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
3%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 ...

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capab ...

CVSS3: 8.8
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться