Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

ubuntu логотип

CVE-2020-25630

около 5 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25629

около 5 лет назад

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-25703

около 5 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25703

около 5 лет назад

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25702

около 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25702

около 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25701

около 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25701

около 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25700

около 5 лет назад

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-25700

около 5 лет назад

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
0%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться