Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2018-14631

почти 8 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-14630

почти 8 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-14630

почти 8 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-14630

почти 8 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-10891

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2018-10891

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2018-10890

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-10890

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-10889

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-10889

около 8 лет назад

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No opt ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2018-14631

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.

CVSS3: 8.8
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
4%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

CVSS3: 8.8
4%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
4%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

CVSS3: 7.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 7.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

CVSS3: 4.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...

CVSS3: 4.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

CVSS3: 4.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No opt ...

CVSS3: 4.3
2%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться