Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541

CVE-2016-2157
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
CVE-2016-2157
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ...

CVE-2016-2156
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.
CVE-2016-2156
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ...

CVE-2016-2155
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
CVE-2016-2155
The grade-reporting feature in Singleview (aka Single View) in Moodle ...

CVE-2016-2154
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.
CVE-2016-2154
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ...

CVE-2016-2153
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.
CVE-2016-2153
Cross-site scripting (XSS) vulnerability in the advanced-search featur ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2016-2157 Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins. | CVSS3: 8.8 | 0% Низкий | больше 9 лет назад |
CVE-2016-2157 Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ... | CVSS3: 8.8 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2016-2156 calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request. | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
CVE-2016-2156 calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ... | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2016-2155 The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role. | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
CVE-2016-2155 The grade-reporting feature in Singleview (aka Single View) in Moodle ... | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2016-2154 admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule. | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
CVE-2016-2154 admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ... | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2016-2153 Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field. | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад |
CVE-2016-2153 Cross-site scripting (XSS) vulnerability in the advanced-search featur ... | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад |
Уязвимостей на страницу