Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2020-1691

больше 3 лет назад

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2020-1691

больше 3 лет назад

In Moodle 3.8, messages required extra sanitizing before updating the ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2020-1754

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-1691

больше 3 лет назад

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-62wh-m4jr-233r

больше 3 лет назад

Moodle LTI module reflected XSS risk

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-wwv7-h477-wrv7

больше 3 лет назад

Moodle Stored XSS and blind SSRF possible via SCORM track details

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp2f-9mx3-3c6p

больше 3 лет назад

Moodle PostScript Code Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-pgm5-cr62-prxq

больше 3 лет назад

Moodle Arbitrary file read when importing lesson questions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-243v-5pff-qqfj

больше 3 лет назад

Moodle Open redirect risk in mobile auto-login feature

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-35653

больше 3 лет назад

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-1754

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-62wh-m4jr-233r

Moodle LTI module reflected XSS risk

CVSS3: 6.1
82%
Высокий
больше 3 лет назад
github логотип
GHSA-wwv7-h477-wrv7

Moodle Stored XSS and blind SSRF possible via SCORM track details

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xp2f-9mx3-3c6p

Moodle PostScript Code Injection

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-pgm5-cr62-prxq

Moodle Arbitrary file read when importing lesson questions

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-243v-5pff-qqfj

Moodle Open redirect risk in mobile auto-login feature

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
82%
Высокий
больше 3 лет назад

Уязвимостей на страницу


Поделиться