Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

nvd логотип

CVE-2016-0725

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-0725

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the search_pagination func ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-0724

больше 9 лет назад

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-0724

больше 9 лет назад

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5342

больше 9 лет назад

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5342

больше 9 лет назад

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5341

больше 9 лет назад

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5341

больше 9 лет назад

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5340

больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5340

больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2. ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-0725

Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-0725

Cross-site scripting (XSS) vulnerability in the search_pagination func ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-0724

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-0724

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5342

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5342

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5341

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5341

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5340

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5340

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2. ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться