Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

nvd логотип

CVE-2015-2270

больше 10 лет назад

lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain sensitive course information via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2270

больше 10 лет назад

lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2269

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-2269

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript- ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-2268

больше 10 лет назад

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2268

больше 10 лет назад

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6. ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2267

больше 10 лет назад

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-2267

больше 10 лет назад

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-2266

больше 10 лет назад

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-2266

больше 10 лет назад

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-2270

lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain sensitive course information via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2270

lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2269

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.

CVSS2: 3.5
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2269

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript- ...

CVSS2: 3.5
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6. ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2267

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2267

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2266

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2266

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться