Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 643
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
BDU:2025-10235
Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя
GHSA-34g7-pg9j-pxgp
Moodle allows IDOR when accessing the cohorts report
GHSA-m367-445c-2xqr
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
GHSA-9vc3-vm42-fjhm
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
GHSA-c8v6-vxhf-wcrr
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
GHSA-hxgg-4qww-85ph
Moodle has reflected Cross-site Scripting risk in policy tool
GHSA-88xj-97gf-7wpq
Moodle has a CSRF risk in user tours manager that allows tour duplication
GHSA-chmf-m33p-ph8m
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
BDU:2025-10235 Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
GHSA-34g7-pg9j-pxgp Moodle allows IDOR when accessing the cohorts report | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-m367-445c-2xqr Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-9vc3-vm42-fjhm Moodle's mod_data edit/delete pages pass CSRF token in GET parameter | CVSS3: 3.1 | 0% Низкий | 8 месяцев назад | |
GHSA-c8v6-vxhf-wcrr Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-hxgg-4qww-85ph Moodle has reflected Cross-site Scripting risk in policy tool | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-88xj-97gf-7wpq Moodle has a CSRF risk in user tours manager that allows tour duplication | CVSS3: 3.5 | 0% Низкий | 8 месяцев назад | |
GHSA-chmf-m33p-ph8m Moodle allows IDOR in RSS block, which allows access to additional RSS feeds | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу