Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2016-2155

больше 9 лет назад

The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2155

больше 9 лет назад

The grade-reporting feature in Singleview (aka Single View) in Moodle ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2154

больше 9 лет назад

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2154

больше 9 лет назад

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2153

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-2153

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the advanced-search featur ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-2152

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-2152

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.ph ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-2151

больше 9 лет назад

user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-2151

больше 9 лет назад

user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x be ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-2155

The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2155

The grade-reporting feature in Singleview (aka Single View) in Moodle ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2154

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2154

admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8 ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2153

Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2153

Cross-site scripting (XSS) vulnerability in the advanced-search featur ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2152

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2152

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.ph ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2151

user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2151

user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x be ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться