Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

nvd логотип

CVE-2014-7838

почти 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-7838

почти 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Foru ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7837

почти 11 лет назад

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2014-7837

почти 11 лет назад

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2014-7836

почти 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-7836

почти 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7835

почти 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-7835

почти 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-7834

почти 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7834

почти 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Foru ...

CVSS2: 6.8
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5.5
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
0%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться