Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2012-2355

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2355

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2354

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2354

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2353

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2353

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-2364

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-2367

больше 13 лет назад

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-2357

больше 13 лет назад

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-2355

больше 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-2354

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-2354

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-2353

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-2353

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2364

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2367

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться