Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2014-7836

около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-7836

около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7835

около 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-7835

около 11 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-7834

около 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7834

около 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7833

около 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7833

около 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7832

около 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7832

около 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
0%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться