Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2012-3392

около 14 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-2367

около 14 лет назад

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2367

около 14 лет назад

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, an ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2366

около 14 лет назад

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-2366

около 14 лет назад

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2. ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-2365

около 14 лет назад

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-2365

около 14 лет назад

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-2364

около 14 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-2364

около 14 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-2363

около 14 лет назад

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2367

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

CVSS2: 4
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2367

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, an ...

CVSS2: 4
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2366

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.

CVSS2: 5.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2366

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2. ...

CVSS2: 5.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2365

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

CVSS2: 3.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2365

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, ...

CVSS2: 3.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2364

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

CVSS2: 3.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2364

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle ...

CVSS2: 3.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2363

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

CVSS2: 6.5
1%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться