Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
GHSA-xp2f-9mx3-3c6p
Moodle PostScript Code Injection
GHSA-243v-5pff-qqfj
Moodle Open redirect risk in mobile auto-login feature
GHSA-wwv7-h477-wrv7
Moodle Stored XSS and blind SSRF possible via SCORM track details
GHSA-pgm5-cr62-prxq
Moodle Arbitrary file read when importing lesson questions
CVE-2022-35653
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
CVE-2022-35653
A reflected XSS issue was identified in the LTI module of Moodle. The ...
CVE-2022-35652
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
CVE-2022-35652
An open redirect issue was found in Moodle due to improper sanitizatio ...
CVE-2022-35651
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.
CVE-2022-35651
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-xp2f-9mx3-3c6p Moodle PostScript Code Injection | CVSS3: 9.8 | 6% Низкий | больше 3 лет назад | |
GHSA-243v-5pff-qqfj Moodle Open redirect risk in mobile auto-login feature | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-wwv7-h477-wrv7 Moodle Stored XSS and blind SSRF possible via SCORM track details | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-pgm5-cr62-prxq Moodle Arbitrary file read when importing lesson questions | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
CVE-2022-35653 A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users. | CVSS3: 6.1 | 78% Высокий | больше 3 лет назад | |
CVE-2022-35653 A reflected XSS issue was identified in the LTI module of Moodle. The ... | CVSS3: 6.1 | 78% Высокий | больше 3 лет назад | |
CVE-2022-35652 An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-35652 An open redirect issue was found in Moodle due to improper sanitizatio ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-35651 A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-35651 A stored XSS and blind SSRF vulnerability was found in Moodle, occurs ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу