Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 646
GHSA-cgvv-3455-824j
Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
BDU:2025-10235
Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя
BDU:2025-11660
Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить провести атаку межсайтового скриптинга (XSS)
GHSA-34g7-pg9j-pxgp
Moodle allows IDOR when accessing the cohorts report
GHSA-cpm7-mv33-jwf8
Moodle's AJAX section delete does not respect course_can_delete_section()
GHSA-m367-445c-2xqr
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
GHSA-hxgg-4qww-85ph
Moodle has reflected Cross-site Scripting risk in policy tool
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-cgvv-3455-824j Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter | CVSS3: 4.2 | 0% Низкий | 8 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ... | CVSS3: 4.2 | 0% Низкий | 8 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 8 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 8 месяцев назад | |
BDU:2025-10235 Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя | CVSS3: 4.2 | 0% Низкий | 8 месяцев назад | |
BDU:2025-11660 Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить провести атаку межсайтового скриптинга (XSS) | CVSS3: 5.7 | 9 месяцев назад | ||
GHSA-34g7-pg9j-pxgp Moodle allows IDOR when accessing the cohorts report | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
GHSA-cpm7-mv33-jwf8 Moodle's AJAX section delete does not respect course_can_delete_section() | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
GHSA-m367-445c-2xqr Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository | CVSS3: 8.8 | 1% Низкий | 10 месяцев назад | |
GHSA-hxgg-4qww-85ph Moodle has reflected Cross-site Scripting risk in policy tool | CVSS3: 5.4 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу