Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 511

nvd логотип

CVE-2018-14630

почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-14630

почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-14630

почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-10891

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2018-10891

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2018-10890

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-10890

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-10889

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-10889

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No opt ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2018-10890

около 7 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

CVSS3: 7.3
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 7.3
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 4.3
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

CVSS3: 4.3
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No opt ...

CVSS3: 4.3
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
0%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться