Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2014-7834

больше 11 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7833

больше 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7833

больше 11 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7832

больше 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7832

больше 11 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7831

больше 11 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7831

больше 11 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7830

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-7830

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-7845

больше 11 лет назад

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not ...

CVSS2: 4
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-7830

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.

CVSS2: 3.5
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-7830

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php ...

CVSS2: 3.5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-7845

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
2%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться