Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-xf6r-r485-49mr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

EPSS: Низкий
github логотип

GHSA-h289-v8rh-2wvj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

EPSS: Низкий
github логотип

GHSA-5488-2xmq-hwfh

больше 3 лет назад

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

EPSS: Низкий
github логотип

GHSA-hxvf-5p7c-7g55

больше 3 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

EPSS: Низкий
github логотип

GHSA-7ghm-fp7p-qvjq

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-58fm-v4pr-jh8p

больше 3 лет назад

Moodle Unrestricted file upload vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vg4g-6rhx-p7rr

больше 3 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-683c-cq88-f22q

больше 3 лет назад

** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g58x-p3pj-rg52

больше 3 лет назад

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6r76-f8c8-fh7p

больше 3 лет назад

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-xf6r-r485-49mr

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-h289-v8rh-2wvj

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-5488-2xmq-hwfh

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hxvf-5p7c-7g55

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7ghm-fp7p-qvjq

Moodle XSS Vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-58fm-v4pr-jh8p

Moodle Unrestricted file upload vulnerability

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-vg4g-6rhx-p7rr

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-683c-cq88-f22q

** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-g58x-p3pj-rg52

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6r76-f8c8-fh7p

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться