Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535

CVE-2020-25703
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.
CVE-2020-25703
The participants table download in Moodle always included user emails, ...

CVE-2020-25702
In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.
CVE-2020-25702
In Moodle, it was possible to include JavaScript when re-naming conten ...

CVE-2020-25701
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
CVE-2020-25701
If the upload course tool in Moodle was used to delete an enrollment m ...

CVE-2020-25700
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
CVE-2020-25700
In moodle, some database module web services allowed students to add e ...

CVE-2020-25699
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
CVE-2020-25699
In moodle, insufficient capability checks could lead to users with the ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2020-25703 The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10. | CVSS3: 5.3 | 0% Низкий | почти 5 лет назад |
CVE-2020-25703 The participants table download in Moodle always included user emails, ... | CVSS3: 5.3 | 0% Низкий | почти 5 лет назад | |
![]() | CVE-2020-25702 In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10. | CVSS3: 6.1 | 0% Низкий | почти 5 лет назад |
CVE-2020-25702 In Moodle, it was possible to include JavaScript when re-naming conten ... | CVSS3: 6.1 | 0% Низкий | почти 5 лет назад | |
![]() | CVE-2020-25701 If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. | CVSS3: 5.3 | 0% Низкий | почти 5 лет назад |
CVE-2020-25701 If the upload course tool in Moodle was used to delete an enrollment m ... | CVSS3: 5.3 | 0% Низкий | почти 5 лет назад | |
![]() | CVE-2020-25700 In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10. | CVSS3: 6.5 | 0% Низкий | почти 5 лет назад |
CVE-2020-25700 In moodle, some database module web services allowed students to add e ... | CVSS3: 6.5 | 0% Низкий | почти 5 лет назад | |
![]() | CVE-2020-25699 In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад |
CVE-2020-25699 In moodle, insufficient capability checks could lead to users with the ... | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад |
Уязвимостей на страницу