Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2012-3396

около 14 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Mo ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3395

около 14 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-3395

около 14 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-3394

около 14 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3394

около 14 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3393

около 14 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-3393

около 14 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Mood ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3392

около 14 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-3392

около 14 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-3391

около 14 лет назад

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-3396

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Mo ...

CVSS2: 3.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3393

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3393

Cross-site scripting (XSS) vulnerability in repository/lib.php in Mood ...

CVSS2: 3.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ...

CVSS2: 5.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3391

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.

CVSS2: 4
1%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться