Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535

CVE-2012-6102
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.

CVE-2012-6106
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.

CVE-2012-5481
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
CVE-2012-5481
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass ...

CVE-2012-5480
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.
CVE-2012-5480
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVE-2012-5479
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
CVE-2012-5479
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, ...

CVE-2012-5473
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
CVE-2012-5473
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI. | CVSS2: 6.4 | 0% Низкий | больше 12 лет назад |
![]() | CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object. | CVSS2: 5.5 | 0% Низкий | больше 12 лет назад |
![]() | CVE-2012-5481 Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
CVE-2012-5481 Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass ... | CVSS2: 4 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-5480 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search. | CVSS2: 6.4 | 0% Низкий | почти 13 лет назад |
CVE-2012-5480 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ... | CVSS2: 6.4 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-5479 The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback. | CVSS2: 6.5 | 1% Низкий | почти 13 лет назад |
CVE-2012-5479 The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, ... | CVSS2: 6.5 | 1% Низкий | почти 13 лет назад | |
![]() | CVE-2012-5473 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
CVE-2012-5473 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ... | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
Уязвимостей на страницу