Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535

CVE-2023-30944
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

BDU:2023-03480
Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной очисткой данных, позволяющая нарушителю выполнять произвольные SQL-запросы в базе данных

BDU:2023-05206
Уязвимость плагина TinyMCE виртуальной обучающей среды Moodle, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных
GHSA-948f-j464-rfj2
Moodle may allow students to bypass sequential navigation during a quiz attempt

CVE-2022-40208
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
CVE-2022-40208
In Moodle, insufficient limitations in some quiz web services made it ...

CVE-2022-40208
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
GHSA-vj5p-fp42-774p
Moodle may display roles to users who don't have access to them
GHSA-q2x3-2f9g-h559
Moodle's Mustache pix helper contained a potential Mustache injection risk if combined with user input
GHSA-56r9-72vx-q989
Moodle arbitrary file read vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2023-30944 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | CVSS3: 5.6 | 1% Низкий | больше 2 лет назад |
![]() | BDU:2023-03480 Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной очисткой данных, позволяющая нарушителю выполнять произвольные SQL-запросы в базе данных | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад |
![]() | BDU:2023-05206 Уязвимость плагина TinyMCE виртуальной обучающей среды Moodle, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных | CVSS3: 5.3 | 18% Средний | больше 2 лет назад |
GHSA-948f-j464-rfj2 Moodle may allow students to bypass sequential navigation during a quiz attempt | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2022-40208 In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
CVE-2022-40208 In Moodle, insufficient limitations in some quiz web services made it ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2022-40208 In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
GHSA-vj5p-fp42-774p Moodle may display roles to users who don't have access to them | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-q2x3-2f9g-h559 Moodle's Mustache pix helper contained a potential Mustache injection risk if combined with user input | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-56r9-72vx-q989 Moodle arbitrary file read vulnerability | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу