Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2016-0724

больше 10 лет назад

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5342

больше 10 лет назад

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5342

больше 10 лет назад

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5341

больше 10 лет назад

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5341

больше 10 лет назад

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5340

больше 10 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5340

больше 10 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2. ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5339

больше 10 лет назад

The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5339

больше 10 лет назад

The core_enrol_get_enrolled_users web service in enrol/externallib.php ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5338

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1) mod/lesson/mediafile.php or (2) mod/lesson/view.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-0724

The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5342

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5342

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x ...

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5341

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5341

mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before ...

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5340

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5340

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2. ...

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5339

The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5339

The core_enrol_get_enrolled_users web service in enrol/externallib.php ...

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5338

Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1) mod/lesson/mediafile.php or (2) mod/lesson/view.php.

CVSS3: 8.8
1%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться