Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541

CVE-2015-3175
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.
CVE-2015-3175
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x ...

CVE-2015-3174
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
CVE-2015-3174
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ...

CVE-2015-2273
Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the student role for a crafted quiz response.
CVE-2015-2273
Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics ...

CVE-2015-2272
login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass a forced-password-change requirement by creating a web-services token.
CVE-2015-2272
login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x bef ...

CVE-2015-2271
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
CVE-2015-2271
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2015-3175 Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header. | CVSS2: 5.8 | 0% Низкий | больше 10 лет назад |
CVE-2015-3175 Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x ... | CVSS2: 5.8 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-3174 mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading. | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад |
CVE-2015-3174 mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ... | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-2273 Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the student role for a crafted quiz response. | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад |
CVE-2015-2273 Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics ... | CVSS2: 3.5 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-2272 login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass a forced-password-change requirement by creating a web-services token. | CVSS2: 4 | 0% Низкий | больше 10 лет назад |
CVE-2015-2272 login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x bef ... | CVSS2: 4 | 0% Низкий | больше 10 лет назад | |
![]() | CVE-2015-2271 tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature. | CVSS2: 4 | 0% Низкий | больше 10 лет назад |
CVE-2015-2271 tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ... | CVSS2: 4 | 0% Низкий | больше 10 лет назад |
Уязвимостей на страницу