Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

nvd логотип

CVE-2011-4279

почти 13 лет назад

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4279

почти 13 лет назад

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setti ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4278

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4278

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the tag autocomplete funct ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4133

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4133

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4291

почти 13 лет назад

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4297

почти 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4281

почти 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4290

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2011-4279

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4279

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setti ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4278

Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4278

Cross-site scripting (XSS) vulnerability in the tag autocomplete funct ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4133

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4133

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before ...

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4291

Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4281

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4290

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться