Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2025-3640

больше 1 года назад

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3628

больше 1 года назад

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3642

больше 1 года назад

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2025-3627

больше 1 года назад

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3643

больше 1 года назад

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-3635

больше 1 года назад

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-3634

больше 1 года назад

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-3634

больше 1 года назад

A security vulnerability was discovered in Moodle that allows students ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3634

больше 1 года назад

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2025-06871

больше 1 года назад

Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2025-3640

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3628

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3642

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3627

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3643

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3635

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-3634

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-3634

A security vulnerability was discovered in Moodle that allows students ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-3634

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-06871

Уязвимость виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться