Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 511
CVE-2013-2246
mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2. ...

CVE-2013-2245
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
CVE-2013-2245
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ...

CVE-2013-2244
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
CVE-2013-2244
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ...

CVE-2013-2243
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
CVE-2013-2243
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ...

CVE-2013-2242
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.
CVE-2013-2242
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ...

CVE-2013-2245
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2013-2246 mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2. ... | CVSS2: 4 | 0% Низкий | около 12 лет назад | |
![]() | CVE-2013-2245 rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed. | CVSS2: 4 | 0% Низкий | около 12 лет назад |
CVE-2013-2245 rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ... | CVSS2: 4 | 0% Низкий | около 12 лет назад | |
![]() | CVE-2013-2244 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | CVSS2: 4.3 | 0% Низкий | около 12 лет назад |
CVE-2013-2244 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ... | CVSS2: 4.3 | 0% Низкий | около 12 лет назад | |
![]() | CVE-2013-2243 mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document. | CVSS2: 4 | 0% Низкий | около 12 лет назад |
CVE-2013-2243 mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ... | CVSS2: 4 | 0% Низкий | около 12 лет назад | |
![]() | CVE-2013-2242 mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server. | CVSS2: 4 | 0% Низкий | около 12 лет назад |
CVE-2013-2242 mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ... | CVSS2: 4 | 0% Низкий | около 12 лет назад | |
![]() | CVE-2013-2245 rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed. | CVSS2: 4 | 0% Низкий | около 12 лет назад |
Уязвимостей на страницу