Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

nvd логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Sc ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerabil ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability a ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-67853

6 месяцев назад

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67855

6 месяцев назад

A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through specially crafted links. Successful exploitation could lead to information disclosure or arbitrary client-side script execution within the user's browser.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Sc ...

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerabil ...

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability a ...

CVSS3: 8.1
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67853

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67855

A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through specially crafted links. Successful exploitation could lead to information disclosure or arbitrary client-side script execution within the user's browser.

CVSS3: 5.4
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться