Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

debian логотип

CVE-2011-4303

почти 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4302

почти 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4302

почти 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4301

почти 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4301

почти 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4300

почти 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4300

почти 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4299

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4299

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4298

почти 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться