Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2012-3391

около 14 лет назад

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-3390

около 14 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-3390

около 14 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3389

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-3389

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3388

около 14 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3388

около 14 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-3387

около 14 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3387

около 14 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-3397

около 14 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-3391

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ...

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3390

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.

CVSS2: 3.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3390

lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 do ...

CVSS2: 3.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3389

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3389

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typesse ...

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3388

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

CVSS2: 4
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3388

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2 ...

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3387

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

CVSS2: 4
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3387

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

CVSS2: 4
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3397

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

CVSS2: 4
1%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться