Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-f6mh-79vh-2hv7

больше 2 лет назад

Cross-site Scripting in Moodle Chat

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-28593

больше 2 лет назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-28593

больше 2 лет назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-28593

больше 2 лет назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qw5-v9cc-v262

больше 2 лет назад

Cross site scripting in moodle

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-29374

больше 2 лет назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-29374

больше 2 лет назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-29374

больше 2 лет назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-29374

больше 2 лет назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-02454

больше 2 лет назад

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных и реализовать межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-f6mh-79vh-2hv7

Cross-site Scripting in Moodle Chat

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qw5-v9cc-v262

Cross site scripting in moodle

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02454

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных и реализовать межсайтовые сценарные атаки

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться