Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

nvd логотип

CVE-2012-3390

почти 13 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-3390

почти 13 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3389

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-3389

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3388

почти 13 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3388

почти 13 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-3387

почти 13 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3387

почти 13 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-3393

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-3394

почти 13 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-3390

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3390

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3389

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3389

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3388

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3388

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3387

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3387

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-3393

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться