Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
CVE-2024-45689
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
CVE-2024-45690
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
CVE-2024-45691
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
CVE-2024-48899
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
GHSA-x3x9-349x-2485
moodle: IDOR in edit/delete RSS feed
GHSA-cq5f-wv7p-5gfc
Moodle leaks user names
GHSA-mg54-p2wj-5ph7
moodle: IDOR when fetching report schedules
GHSA-fjq9-452g-jg3q
moodle: Some users can delete audiences of other reports
CVE-2024-48901
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
CVE-2024-48901
A vulnerability was found in Moodle. Additional checks are required to ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-45689 A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
CVE-2024-45690 A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
CVE-2024-45691 A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
CVE-2024-48899 A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-x3x9-349x-2485 moodle: IDOR in edit/delete RSS feed | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-cq5f-wv7p-5gfc Moodle leaks user names | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-mg54-p2wj-5ph7 moodle: IDOR when fetching report schedules | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-fjq9-452g-jg3q moodle: Some users can delete audiences of other reports | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
CVE-2024-48901 A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
CVE-2024-48901 A vulnerability was found in Moodle. Additional checks are required to ... | CVSS3: 4.3 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу