Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
CVE-2024-34001
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-33998
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
CVE-2024-33997
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
CVE-2024-33999
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
BDU:2024-05157
Уязвимость системы управления Moodle, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнять произвольные команды
GHSA-f6mh-79vh-2hv7
Cross-site Scripting in Moodle Chat
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
GHSA-3qw5-v9cc-v262
Cross site scripting in moodle
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-34001 Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-33998 Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. | CVSS3: 5.4 | 1% Низкий | больше 1 года назад | |
CVE-2024-33997 Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation. | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-33999 The referrer URL used by MFA required additional sanitizing, rather than being used directly. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
BDU:2024-05157 Уязвимость системы управления Moodle, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнять произвольные команды | CVSS3: 6.2 | 0% Низкий | больше 1 года назад | |
GHSA-f6mh-79vh-2hv7 Cross-site Scripting in Moodle Chat | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle." | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentia ... | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle." | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
GHSA-3qw5-v9cc-v262 Cross site scripting in moodle | CVSS3: 6.1 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу