Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2015-0217

больше 10 лет назад

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0217

больше 10 лет назад

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2. ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0216

больше 10 лет назад

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-0216

больше 10 лет назад

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-0215

больше 10 лет назад

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-0215

больше 10 лет назад

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-0214

больше 10 лет назад

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-0214

больше 10 лет назад

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2 ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-0213

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0213

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) edit ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2. ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0216

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0216

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0215

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0215

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0214

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0214

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2 ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) edit ...

CVSS2: 6.8
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться