Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

ubuntu логотип

CVE-2022-30598

больше 3 лет назад

A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-30600

больше 3 лет назад

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk alloca ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xf6r-r485-49mr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

EPSS: Низкий
github логотип

GHSA-h289-v8rh-2wvj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

EPSS: Низкий
github логотип

GHSA-5488-2xmq-hwfh

больше 3 лет назад

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

EPSS: Низкий
github логотип

GHSA-hxvf-5p7c-7g55

больше 3 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

EPSS: Низкий
github логотип

GHSA-7ghm-fp7p-qvjq

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-30598

A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-30600

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk alloca ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xf6r-r485-49mr

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-h289-v8rh-2wvj

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-5488-2xmq-hwfh

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hxvf-5p7c-7g55

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7ghm-fp7p-qvjq

Moodle XSS Vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться