Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2020-25702

больше 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25701

больше 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25701

больше 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25700

больше 5 лет назад

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-25700

больше 5 лет назад

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-25699

больше 5 лет назад

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25699

больше 5 лет назад

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-25698

больше 5 лет назад

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25698

больше 5 лет назад

Users' enrollment capabilities were not being sufficiently checked in ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25702

больше 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in ...

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться