Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2025-67849

6 месяцев назад

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67857

6 месяцев назад

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-67856

6 месяцев назад

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-67852

6 месяцев назад

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2025-67851

6 месяцев назад

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvmh-25jw-gmmm

6 месяцев назад

Moodle affected by a code injection vulnerability

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-67847

6 месяцев назад

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-67847

6 месяцев назад

A flaw was found in Moodle. An attacker with access to the restore int ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2025-67847

6 месяцев назад

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-px56-6vfj-h8xp

6 месяцев назад

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67857

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67856

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67852

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

CVSS3: 3.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67851

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvmh-25jw-gmmm

Moodle affected by a code injection vulnerability

CVSS3: 8.8
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-67847

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
debian логотип
CVE-2025-67847

A flaw was found in Moodle. An attacker with access to the restore int ...

CVSS3: 8.8
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-67847

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-px56-6vfj-h8xp

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVSS3: 7.2
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться