Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2012-2358

около 14 лет назад

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-2357

около 14 лет назад

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-2357

около 14 лет назад

The Multi-Authentication feature in the Central Authentication Service ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2356

около 14 лет назад

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2356

около 14 лет назад

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2355

около 14 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2355

около 14 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2354

около 14 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2354

около 14 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2353

около 14 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 ...

CVSS2: 5.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service ...

CVSS2: 5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2356

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2356

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x ...

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2354

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

CVSS2: 4
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-2354

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2353

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

CVSS2: 4
1%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться