Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2014-3542

около 12 лет назад

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-3541

около 12 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-3541

около 12 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4. ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-3550

около 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted (1) error or (2) success message for a scheduled task.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3549

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3542

около 12 лет назад

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3552

около 12 лет назад

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2014-3546

около 12 лет назад

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-3553

около 12 лет назад

mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-3541

около 12 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-3542

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5 ...

CVSS2: 4.3
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
4%
Низкий
около 12 лет назад
debian логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4. ...

CVSS2: 7.5
4%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3550

Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted (1) error or (2) success message for a scheduled task.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3549

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3542

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3552

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

CVSS2: 6
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3546

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

CVSS2: 5
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3553

mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships.

CVSS2: 4.9
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
4%
Низкий
около 12 лет назад

Уязвимостей на страницу


Поделиться