Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

fstec логотип

BDU:2021-03914

около 5 лет назад

Уязвимость системы управления Moodle, связанная с непринятием мер по защите SQL запроса, позволяющая нарушителю выполнять произвольный код

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-21809

около 5 лет назад

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

CVSS3: 9.1
EPSS: Средний
ubuntu логотип

CVE-2021-21809

около 5 лет назад

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

CVSS3: 9.1
EPSS: Средний
nvd логотип

CVE-2021-32244

около 5 лет назад

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-32244

около 5 лет назад

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-32244

около 5 лет назад

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-14827

около 5 лет назад

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14827

около 5 лет назад

A vulnerability was found in Moodle where javaScript injection was pos ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14827

около 5 лет назад

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2021-02738

около 5 лет назад

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный HTML-код и код сценария в браузере пользователя в контексте уязвимого веб-сайта

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2021-03914

Уязвимость системы управления Moodle, связанная с непринятием мер по защите SQL запроса, позволяющая нарушителю выполнять произвольный код

CVSS3: 8.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-21809

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

CVSS3: 9.1
24%
Средний
около 5 лет назад
ubuntu логотип
CVE-2021-21809

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

CVSS3: 9.1
24%
Средний
около 5 лет назад
nvd логотип
CVE-2021-32244

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

CVSS3: 5.4
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-32244

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to ...

CVSS3: 5.4
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-32244

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

CVSS3: 5.4
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2019-14827

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2019-14827

A vulnerability was found in Moodle where javaScript injection was pos ...

CVSS3: 6.1
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2019-14827

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
fstec логотип
BDU:2021-02738

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный HTML-код и код сценария в браузере пользователя в контексте уязвимого веб-сайта

CVSS3: 7.2
1%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться