Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

nvd логотип

CVE-2016-2157

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-2157

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-2156

больше 9 лет назад

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2156

больше 9 лет назад

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2155

больше 9 лет назад

The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2155

больше 9 лет назад

The grade-reporting feature in Singleview (aka Single View) in Moodle ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2154

больше 9 лет назад

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2154

больше 9 лет назад

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2153

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-2153

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the advanced-search featur ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ...

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2156

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2156

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2155

The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2155

The grade-reporting feature in Singleview (aka Single View) in Moodle ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2154

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2154

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2153

Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2153

Cross-site scripting (XSS) vulnerability in the advanced-search featur ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться