Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2015-3273

больше 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3272

больше 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2015-3272

больше 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-5267

больше 10 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3275

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-5332

больше 10 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-3274

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-3273

больше 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5342

больше 10 лет назад

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5266

больше 10 лет назад

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5342

The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
2%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться