Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

debian логотип

CVE-2013-4942

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the U ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4941

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4941

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4940

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4940

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility c ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4939

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4939

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility c ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4938

больше 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4938

больше 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2246

больше 12 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-4942

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the U ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4941

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4941

Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4940

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4940

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility c ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4939

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4939

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility c ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2246

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться