Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 469

CVE-2024-48896
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
GHSA-g8r3-2v89-j6r5
Moodle IDOR when accessing list of badge recipients
CVE-2024-48900
A vulnerability was found in Moodle. Additional checks are required to ...

CVE-2024-48900
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

CVE-2024-48900
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
GHSA-hjgc-jxjc-8v9j
Moodle reflected XSS via H5P error message
CVE-2024-43439
A flaw was found in moodle. H5P error messages require additional sani ...

CVE-2024-43439
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

CVE-2024-43439
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
GHSA-4hjf-6pxr-549h
Moodle Cross-site Scripting vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2024-48896 A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад |
GHSA-g8r3-2v89-j6r5 Moodle IDOR when accessing list of badge recipients | 0% Низкий | 7 месяцев назад | ||
CVE-2024-48900 A vulnerability was found in Moodle. Additional checks are required to ... | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
![]() | CVE-2024-48900 A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад |
![]() | CVE-2024-48900 A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад |
GHSA-hjgc-jxjc-8v9j Moodle reflected XSS via H5P error message | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
CVE-2024-43439 A flaw was found in moodle. H5P error messages require additional sani ... | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
![]() | CVE-2024-43439 A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад |
![]() | CVE-2024-43439 A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад |
GHSA-4hjf-6pxr-549h Moodle Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу