Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

nvd логотип

CVE-2020-25703

почти 5 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25703

почти 5 лет назад

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25702

почти 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25702

почти 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25701

почти 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25701

почти 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25700

почти 5 лет назад

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-25700

почти 5 лет назад

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-25699

почти 5 лет назад

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25699

почти 5 лет назад

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться