Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 511

debian логотип

CVE-2014-0216

больше 11 лет назад

The My Home implementation in the block_html_pluginfile function in bl ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-0215

больше 11 лет назад

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0215

больше 11 лет назад

The blind-marking implementation in Moodle through 2.3.11, 2.4.x befor ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-0214

больше 11 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0214

больше 11 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x b ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0213

больше 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0213

больше 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assi ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0216

больше 11 лет назад

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-0215

больше 11 лет назад

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-0213

больше 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-0216

The My Home implementation in the block_html_pluginfile function in bl ...

CVSS2: 5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0215

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0215

The blind-marking implementation in Moodle through 2.3.11, 2.4.x befor ...

CVSS2: 4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x b ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assi ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0216

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

CVSS2: 5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0215

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться