Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

nvd логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Sc ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerabil ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability a ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-67850

6 месяцев назад

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67857

6 месяцев назад

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67848

6 месяцев назад

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Sc ...

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerabil ...

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability a ...

CVSS3: 8.1
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67857

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

CVSS3: 8.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться