Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2011-4290

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4289

около 14 лет назад

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4289

около 14 лет назад

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4288

около 14 лет назад

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4288

около 14 лет назад

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly im ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4287

около 14 лет назад

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4287

около 14 лет назад

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4286

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4286

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the media-filte ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4285

около 14 лет назад

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.

CVSS2: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4290

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php ...

CVSS2: 4.3
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4289

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

CVSS2: 4
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4289

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting ...

CVSS2: 4
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4288

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

CVSS2: 4
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4288

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly im ...

CVSS2: 4
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4287

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

CVSS2: 6.8
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4287

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force ...

CVSS2: 6.8
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4286

Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4286

Multiple cross-site scripting (XSS) vulnerabilities in the media-filte ...

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4285

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.

CVSS2: 5.5
2%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться