Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

nvd логотип

CVE-2023-35131

больше 2 лет назад

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-35131

больше 2 лет назад

Content on the groups page required additional sanitizing to prevent a ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-35132

больше 2 лет назад

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2023-35131

больше 2 лет назад

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-35133

больше 2 лет назад

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w2pm-fr62-jgv4

больше 2 лет назад

Moodle vulnerable to stored Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-27131

больше 2 лет назад

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user account cookies by storing the malicious XSS payload in Header and Footer. NOTE: this is disputed by the vendor because the "Additional HTML Section" for "Header and Footer" can only be supplied by an administrator, who is intentionally allowed to enter unsanitized input (e.g., site-specific JavaScript).

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-27131

больше 2 лет назад

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-27131

больше 2 лет назад

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user account cookies by storing the malicious XSS payload in Header and Footer. NOTE: this is disputed by the vendor because the "Additional HTML Section" for "Header and Footer" can only be supplied by an administrator, who is intentionally allowed to enter unsanitized input (e.g., site-specific JavaScript).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22gj-8qj2-fj46

больше 2 лет назад

Moodle External Control of File Name or Path vulnerability

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent a ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-35132

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w2pm-fr62-jgv4

Moodle vulnerable to stored Cross-site Scripting

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2021-27131

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user account cookies by storing the malicious XSS payload in Header and Footer. NOTE: this is disputed by the vendor because the "Additional HTML Section" for "Header and Footer" can only be supplied by an administrator, who is intentionally allowed to enter unsanitized input (e.g., site-specific JavaScript).

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2021-27131

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2021-27131

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user account cookies by storing the malicious XSS payload in Header and Footer. NOTE: this is disputed by the vendor because the "Additional HTML Section" for "Header and Footer" can only be supplied by an administrator, who is intentionally allowed to enter unsanitized input (e.g., site-specific JavaScript).

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22gj-8qj2-fj46

Moodle External Control of File Name or Path vulnerability

CVSS3: 5.3
18%
Средний
больше 2 лет назад

Уязвимостей на страницу


Поделиться