Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541

CVE-2015-5265
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
CVE-2015-5265
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8. ...

CVE-2015-5264
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
CVE-2015-5264
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVE-2015-3275
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
CVE-2015-3275
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...

CVE-2015-3274
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.
CVE-2015-3274
Cross-site scripting (XSS) vulnerability in the user_get_user_details ...

CVE-2015-3273
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.
CVE-2015-3273
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2015-5265 The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor. | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
CVE-2015-5265 The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8. ... | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2015-5264 The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role. | CVSS3: 5.4 | 0% Низкий | больше 9 лет назад |
CVE-2015-5264 The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ... | CVSS3: 5.4 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2015-3275 Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php. | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад |
CVE-2015-3275 Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ... | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2015-3274 Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service. | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад |
CVE-2015-3274 Cross-site scripting (XSS) vulnerability in the user_get_user_details ... | CVSS3: 6.1 | 0% Низкий | больше 9 лет назад | |
![]() | CVE-2015-3273 mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization. | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
CVE-2015-3273 mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ... | CVSS3: 4.3 | 0% Низкий | больше 9 лет назад |
Уязвимостей на страницу