Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

nvd логотип

CVE-2019-10133

около 7 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2019-10133

около 7 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10133

около 7 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10154

около 7 лет назад

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10134

около 7 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2019-3847

больше 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2019-3847

больше 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2019-3847

больше 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2019-3852

больше 7 лет назад

A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3852

больше 7 лет назад

A vulnerability was found in moodle before version 3.6.3. The get_with ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.1
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-10134

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
2%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-3852

A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

CVSS3: 4.3
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-3852

A vulnerability was found in moodle before version 3.6.3. The get_with ...

CVSS3: 4.3
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться