Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2015-3178

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3178

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3177

больше 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3177

больше 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3176

больше 10 лет назад

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3176

больше 10 лет назад

The account-confirmation feature in login/confirm.php in Moodle throug ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3175

больше 10 лет назад

Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2015-3175

больше 10 лет назад

Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x ...

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2015-3174

больше 10 лет назад

mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3174

больше 10 лет назад

mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3176

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3176

The account-confirmation feature in login/confirm.php in Moodle throug ...

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3175

Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.

CVSS2: 5.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3175

Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x ...

CVSS2: 5.8
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3174

mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3174

mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться