Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535

CVE-2012-6103
Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.
CVE-2012-6103
Multiple cross-site request forgery (CSRF) vulnerabilities in user/mes ...

CVE-2012-6102
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
CVE-2012-6102
lib.php in the Submission comments plugin in the Assignment module in ...

CVE-2012-6101
Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.
CVE-2012-6101
Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2 ...

CVE-2012-6100
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
CVE-2012-6100
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2. ...

CVE-2012-6099
The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.
CVE-2012-6099
The moodle1 backup converter in backup/converter/moodle1/lib.php in Mo ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages. | CVSS2: 6.8 | 0% Низкий | больше 12 лет назад |
CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/mes ... | CVSS2: 6.8 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI. | CVSS2: 6.4 | 0% Низкий | больше 12 лет назад |
CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in ... | CVSS2: 6.4 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-6101 Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php. | CVSS2: 5.8 | 0% Низкий | больше 12 лет назад |
CVE-2012-6101 Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2 ... | CVSS2: 5.8 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-6100 report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report. | CVSS2: 4 | 0% Низкий | больше 12 лет назад |
CVE-2012-6100 report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2. ... | CVSS2: 4 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-6099 The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature. | CVSS2: 4 | 0% Низкий | больше 12 лет назад |
CVE-2012-6099 The moodle1 backup converter in backup/converter/moodle1/lib.php in Mo ... | CVSS2: 4 | 0% Низкий | больше 12 лет назад |
Уязвимостей на страницу