Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
CVE-2012-2363
SQL injection vulnerability in calendar/event.php in the calendar impl ...
CVE-2012-2362
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
CVE-2012-2362
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog i ...
CVE-2012-2361
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
CVE-2012-2361
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ...
CVE-2012-2360
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.
CVE-2012-2360
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Mood ...
CVE-2012-2359
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
CVE-2012-2359
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2. ...
CVE-2012-2358
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-2363 SQL injection vulnerability in calendar/event.php in the calendar impl ... | CVSS2: 6.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2362 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php. | CVSS2: 2.6 | 1% Низкий | около 14 лет назад | |
CVE-2012-2362 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog i ... | CVSS2: 2.6 | 1% Низкий | около 14 лет назад | |
CVE-2012-2361 Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | CVSS2: 3.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2361 Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ... | CVSS2: 3.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2360 Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title. | CVSS2: 3.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2360 Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Mood ... | CVSS2: 3.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2359 admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability. | CVSS2: 6.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2359 admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2. ... | CVSS2: 6.5 | 1% Низкий | около 14 лет назад | |
CVE-2012-2358 Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist. | CVSS2: 5.5 | 2% Низкий | около 14 лет назад |
Уязвимостей на страницу