Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 643

nvd логотип

CVE-2025-53021

6 месяцев назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2025-53021

6 месяцев назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2025-10235

6 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-34g7-pg9j-pxgp

8 месяцев назад

Moodle allows IDOR when accessing the cohorts report

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m367-445c-2xqr

8 месяцев назад

Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9vc3-vm42-fjhm

8 месяцев назад

Moodle's mod_data edit/delete pages pass CSRF token in GET parameter

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-c8v6-vxhf-wcrr

8 месяцев назад

Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hxgg-4qww-85ph

8 месяцев назад

Moodle has reflected Cross-site Scripting risk in policy tool

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-88xj-97gf-7wpq

8 месяцев назад

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-chmf-m33p-ph8m

8 месяцев назад

Moodle allows IDOR in RSS block, which allows access to additional RSS feeds

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-10235

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-34g7-pg9j-pxgp

Moodle allows IDOR when accessing the cohorts report

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-m367-445c-2xqr

Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-9vc3-vm42-fjhm

Moodle's mod_data edit/delete pages pass CSRF token in GET parameter

CVSS3: 3.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-c8v6-vxhf-wcrr

Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-hxgg-4qww-85ph

Moodle has reflected Cross-site Scripting risk in policy tool

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-88xj-97gf-7wpq

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-chmf-m33p-ph8m

Moodle allows IDOR in RSS block, which allows access to additional RSS feeds

CVSS3: 4.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу


Поделиться