Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

debian логотип

CVE-2014-7836

почти 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7835

почти 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-7835

почти 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-7834

почти 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7834

почти 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7833

почти 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7833

почти 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7832

почти 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7832

почти 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7831

почти 11 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
0%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться