Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 470

CVE-2024-25979
The URL parameters accepted by forum search were not limited to the allowed parameters.

CVE-2024-25983
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVE-2024-25978
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

CVE-2024-25982
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVE-2024-25981
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVE-2024-25980
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
GHSA-5p2x-8427-9fgp
Moodle Improper Access Control vulnerability

CVE-2024-1439
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
CVE-2024-1439
Inadequate access control in Moodle LMS. This vulnerability could allo ...

CVE-2024-1439
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2024-25979 The URL parameters accepted by forum search were not limited to the allowed parameters. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | CVSS3: 3.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25978 Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25982 The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25980 Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
GHSA-5p2x-8427-9fgp Moodle Improper Access Control vulnerability | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-1439 Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
CVE-2024-1439 Inadequate access control in Moodle LMS. This vulnerability could allo ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-1439 Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу