Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
CVE-2019-3851
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ...
CVE-2019-3850
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
CVE-2019-3850
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...
CVE-2019-3849
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
CVE-2019-3849
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...
CVE-2019-3848
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
CVE-2019-3848
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...
CVE-2019-3849
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
CVE-2019-3850
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
CVE-2019-3851
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-3851 A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ... | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3850 A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits. | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3850 A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ... | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3849 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3849 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ... | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3848 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.) | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3848 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ... | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3849 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3850 A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits. | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-3851 A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу