Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

ubuntu логотип

CVE-2024-25979

больше 1 года назад

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25983

больше 1 года назад

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2024-25978

больше 1 года назад

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-25982

больше 1 года назад

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25981

больше 1 года назад

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25980

больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5p2x-8427-9fgp

больше 1 года назад

Moodle Improper Access Control vulnerability

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1439

больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1439

больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allo ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-1439

больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-25979

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25978

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25982

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-5p2x-8427-9fgp

Moodle Improper Access Control vulnerability

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-1439

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-1439

Inadequate access control in Moodle LMS. This vulnerability could allo ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-1439

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться