Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541

CVE-2015-3180
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
CVE-2015-3180
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVE-2015-3179
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
CVE-2015-3179
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...

CVE-2015-3178
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
CVE-2015-3178
Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVE-2015-3177
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
CVE-2015-3177
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ...

CVE-2015-3176
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.
CVE-2015-3176
The account-confirmation feature in login/confirm.php in Moodle throug ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2015-3180 lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment. | CVSS2: 4 | 0% Низкий | больше 10 лет назад |
CVE-2015-3180 lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ... | CVSS2: 4 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-3179 login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account. | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад |
CVE-2015-3179 login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ... | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-3178 Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services. | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад |
CVE-2015-3178 Cross-site scripting (XSS) vulnerability in the external_format_text f ... | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-3177 Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request. | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад |
CVE-2015-3177 Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ... | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-3176 The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register. | CVSS2: 4.3 | 0% Низкий | больше 10 лет назад |
CVE-2015-3176 The account-confirmation feature in login/confirm.php in Moodle throug ... | CVSS2: 4.3 | 0% Низкий | больше 10 лет назад |
Уязвимостей на страницу