Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

debian логотип

CVE-2013-2244

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2243

больше 12 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2243

больше 12 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2242

больше 12 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2242

больше 12 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-4939

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4940

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2244

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2245

больше 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2246

больше 12 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-2244

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2243

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2243

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2242

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2242

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-4939

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-4940

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2244

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2245

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2246

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться