Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

ubuntu логотип

CVE-2024-34001

больше 1 года назад

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.4
EPSS: Низкий
ubuntu логотип

CVE-2024-33998

больше 1 года назад

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-33997

больше 1 года назад

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-33999

больше 1 года назад

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-05157

больше 1 года назад

Уязвимость системы управления Moodle, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнять произвольные команды

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-f6mh-79vh-2hv7

почти 2 года назад

Cross-site Scripting in Moodle Chat

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-28593

почти 2 года назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-28593

почти 2 года назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-28593

почти 2 года назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qw5-v9cc-v262

почти 2 года назад

Cross site scripting in moodle

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-34001

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-33998

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-33997

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-33999

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-05157

Уязвимость системы управления Moodle, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнять произвольные команды

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-f6mh-79vh-2hv7

Cross-site Scripting in Moodle Chat

CVSS3: 5.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qw5-v9cc-v262

Cross site scripting in moodle

CVSS3: 6.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться