Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
GHSA-995f-r3qg-j3mx
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.
GHSA-m55g-vpgh-vw7c
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
GHSA-c6g7-c2cg-grhj
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.
GHSA-jj3p-6mw3-6qmm
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").
GHSA-2m72-m5cw-3g9h
Missing permission check in Moodle
GHSA-grj4-g57c-9xmv
Moodle Bypass email verification secret when confirming account registration
GHSA-h7h6-fwpv-ggvx
Moodle contains Stored XSS via ID number user profile field
GHSA-2jrm-gww7-wch2
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
GHSA-h8m4-h385-qhqv
Moodle Cross-site Scripting
GHSA-c3j6-33r4-89q3
Moodle Client side denial of service via personal message
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-995f-r3qg-j3mx A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-m55g-vpgh-vw7c A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-c6g7-c2cg-grhj A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role. | 0% Низкий | больше 3 лет назад | ||
GHSA-jj3p-6mw3-6qmm A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app"). | CVSS3: 6.1 | 2% Низкий | больше 3 лет назад | |
GHSA-2m72-m5cw-3g9h Missing permission check in Moodle | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-grj4-g57c-9xmv Moodle Bypass email verification secret when confirming account registration | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-h7h6-fwpv-ggvx Moodle contains Stored XSS via ID number user profile field | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-2jrm-gww7-wch2 Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration | CVSS3: 7.2 | 1% Низкий | больше 3 лет назад | |
GHSA-h8m4-h385-qhqv Moodle Cross-site Scripting | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-c3j6-33r4-89q3 Moodle Client side denial of service via personal message | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу