Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2015-5331

больше 10 лет назад

Moodle 2.9.x before 2.9.3 does not properly check the contact list bef ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5272

больше 10 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5272

больше 10 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authentic ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5269

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2015-5269

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in group/overview.php in Mood ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2015-5268

больше 10 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5268

больше 10 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5267

больше 10 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-5267

больше 10 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-5266

больше 10 лет назад

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-5331

Moodle 2.9.x before 2.9.3 does not properly check the contact list bef ...

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5272

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5272

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authentic ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Mood ...

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 7.5
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
2%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться