Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535

CVE-2012-3392
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.
CVE-2012-3392
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ...

CVE-2012-3391
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.
CVE-2012-3391
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ...

CVE-2012-3390
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.
CVE-2012-3390
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ...

CVE-2012-3389
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.
CVE-2012-3389
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ...

CVE-2012-3388
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
CVE-2012-3388
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2012-3392 mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums. | CVSS2: 5.5 | 0% Низкий | около 13 лет назад |
CVE-2012-3392 mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ... | CVSS2: 5.5 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2012-3391 mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum. | CVSS2: 4 | 0% Низкий | около 13 лет назад |
CVE-2012-3391 mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ... | CVSS2: 4 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2012-3390 lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block. | CVSS2: 3.5 | 0% Низкий | около 13 лет назад |
CVE-2012-3390 lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ... | CVSS2: 3.5 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2012-3389 Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter. | CVSS2: 4.3 | 0% Низкий | около 13 лет назад |
CVE-2012-3389 Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ... | CVSS2: 4.3 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2012-3388 The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record. | CVSS2: 4 | 0% Низкий | около 13 лет назад |
CVE-2012-3388 The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ... | CVSS2: 4 | 0% Низкий | около 13 лет назад |
Уязвимостей на страницу