Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 470
CVE-2010-1617
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 doe ...

CVE-2010-1616
Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.
CVE-2010-1616
Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restorin ...

CVE-2010-1615
Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms elements" related to lib/form/selectgroups.php.
CVE-2010-1615
Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 a ...

CVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.
CVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x be ...

CVE-2010-1613
Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.
CVE-2010-1613
Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate se ...

CVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2010-1617 user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 doe ... | CVSS2: 4 | 0% Низкий | около 15 лет назад | |
![]() | CVE-2010-1616 Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability. | CVSS2: 4 | 0% Низкий | около 15 лет назад |
CVE-2010-1616 Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restorin ... | CVSS2: 4 | 0% Низкий | около 15 лет назад | |
![]() | CVE-2010-1615 Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms elements" related to lib/form/selectgroups.php. | CVSS2: 7.5 | 0% Низкий | около 15 лет назад |
CVE-2010-1615 Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 a ... | CVSS2: 7.5 | 0% Низкий | около 15 лет назад | |
![]() | CVE-2010-1614 Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability. | CVSS2: 4.3 | 0% Низкий | около 15 лет назад |
CVE-2010-1614 Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x be ... | CVSS2: 4.3 | 0% Низкий | около 15 лет назад | |
![]() | CVE-2010-1613 Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks. | CVSS2: 6.8 | 0% Низкий | около 15 лет назад |
CVE-2010-1613 Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate se ... | CVSS2: 6.8 | 0% Низкий | около 15 лет назад | |
![]() | CVE-2010-1614 Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability. | CVSS2: 4.3 | 0% Низкий | около 15 лет назад |
Уязвимостей на страницу