Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
CVE-2012-6112
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellcheck ...
CVE-2012-6106
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.
CVE-2012-6106
calendar/managesubscriptions.php in the Manage Subscriptions implement ...
CVE-2012-6105
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
CVE-2012-6105
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3 ...
CVE-2012-6104
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
CVE-2012-6104
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and ...
CVE-2012-6103
Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.
CVE-2012-6103
Multiple cross-site request forgery (CSRF) vulnerabilities in user/mes ...
CVE-2012-6102
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-6112 classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellcheck ... | CVSS2: 5 | 2% Низкий | больше 13 лет назад | |
CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object. | CVSS2: 5.5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implement ... | CVSS2: 5.5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6105 blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed. | CVSS2: 5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6105 blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3 ... | CVSS2: 5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6104 blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed. | CVSS2: 5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6104 blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and ... | CVSS2: 5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages. | CVSS2: 6.8 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/mes ... | CVSS2: 6.8 | 1% Низкий | больше 13 лет назад | |
CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI. | CVSS2: 6.4 | 1% Низкий | больше 13 лет назад |
Уязвимостей на страницу