Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2014-0216

около 12 лет назад

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-0218

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-0213

около 12 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0214

около 12 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-2572

больше 12 лет назад

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-2572

больше 12 лет назад

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not prope ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-2571

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-2571

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-0129

больше 12 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-0127

больше 12 лет назад

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2014-0216

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

CVSS2: 5
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-0218

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
3%
Низкий
около 12 лет назад
nvd логотип
CVE-2014-2572

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-2572

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not prope ...

CVSS2: 4
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
2%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться