Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

debian логотип

CVE-2014-2571

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-0127

больше 11 лет назад

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2014-0129

больше 11 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0129

больше 11 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6. ...

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0127

больше 11 лет назад

The time-validation implementation in (1) mod/feedback/complete.php an ...

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2014-0126

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0125

больше 11 лет назад

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2014-0126

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0125

больше 11 лет назад

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4 ...

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-0124

больше 11 лет назад

The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6. ...

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php an ...

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4 ...

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0124

The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.

CVSS2: 4
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться