Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2015-3275

почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-3275

почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-3274

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-3274

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-3273

почти 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3273

почти 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3272

почти 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2015-3272

почти 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-5336

почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-5341

почти 10 лет назад

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...

CVSS3: 6.1
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details ...

CVSS3: 6.1
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-5336

Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-5341

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
0%
Низкий
почти 10 лет назад

Уязвимостей на страницу


Поделиться