Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 474
GHSA-w8x2-w4qr-v3x4
Moodle Code Injection vulnerability

CVE-2023-5551
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
CVE-2023-5551
Separate Groups mode restrictions were not honoured in the forum summa ...

CVE-2023-5550
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
CVE-2023-5550
In a shared hosting environment that has been misconfigured to allow a ...

CVE-2023-5549
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
CVE-2023-5549
Insufficient web service capability checks made it possible to move ca ...

CVE-2023-5548
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
CVE-2023-5548
Stronger revision number limitations were required on file serving end ...

CVE-2023-5547
The course upload preview contained an XSS risk for users uploading unsafe data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-w8x2-w4qr-v3x4 Moodle Code Injection vulnerability | CVSS3: 8.8 | 2% Низкий | почти 2 года назад | |
![]() | CVE-2023-5551 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад |
CVE-2023-5551 Separate Groups mode restrictions were not honoured in the forum summa ... | CVSS3: 3.3 | 0% Низкий | почти 2 года назад | |
![]() | CVE-2023-5550 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution. | CVSS3: 6.5 | 1% Низкий | почти 2 года назад |
CVE-2023-5550 In a shared hosting environment that has been misconfigured to allow a ... | CVSS3: 6.5 | 1% Низкий | почти 2 года назад | |
![]() | CVE-2023-5549 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад |
CVE-2023-5549 Insufficient web service capability checks made it possible to move ca ... | CVSS3: 3.3 | 0% Низкий | почти 2 года назад | |
![]() | CVE-2023-5548 Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад |
CVE-2023-5548 Stronger revision number limitations were required on file serving end ... | CVSS3: 3.3 | 0% Низкий | почти 2 года назад | |
![]() | CVE-2023-5547 The course upload preview contained an XSS risk for users uploading unsafe data. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу