Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2016-2190

больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-2190

больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-2159

больше 9 лет назад

The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2159

больше 9 лет назад

The save_submission function in mod/assign/externallib.php in Moodle t ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2158

больше 9 лет назад

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2158

больше 9 лет назад

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.1 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2157

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-2157

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-2156

больше 9 лет назад

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2156

больше 9 лет назад

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-2190

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2190

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x ...

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2159

The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for a web-service request.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2159

The save_submission function in mod/assign/externallib.php in Moodle t ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2158

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2158

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.1 ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminman ...

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2156

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2156

calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13 ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться