Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2019-3852

почти 7 лет назад

A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3852

почти 7 лет назад

A vulnerability was found in moodle before version 3.6.3. The get_with ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3851

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3851

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3850

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3850

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3849

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3852

A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3852

A vulnerability was found in moodle before version 3.6.3. The get_with ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3851

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3851

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться