Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-qm6h-hvwq-4xp6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.

EPSS: Низкий
github логотип

GHSA-7p9m-wjgf-7xr6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

EPSS: Низкий
github логотип

GHSA-4r4x-49qh-hfgv

больше 3 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

EPSS: Низкий
github логотип

GHSA-phqj-xp48-7p7c

больше 3 лет назад

Moodle does not use the forceloginforprofiles setting for course-profiles access control

EPSS: Низкий
github логотип

GHSA-4fm4-pcw7-99hg

больше 3 лет назад

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

EPSS: Низкий
github логотип

GHSA-m97f-x4mr-4x3q

больше 3 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-p586-c547-p893

больше 3 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

EPSS: Низкий
github логотип

GHSA-79w6-7hhc-89m9

больше 3 лет назад

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

EPSS: Низкий
github логотип

GHSA-jcrj-x36p-h9f6

больше 3 лет назад

Moodle Open Redirect in Calendar Set Page

EPSS: Низкий
github логотип

GHSA-62wv-866c-rh86

больше 3 лет назад

Moodle does not properly restrict comment capabilities

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-qm6h-hvwq-4xp6

Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7p9m-wjgf-7xr6

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4r4x-49qh-hfgv

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-phqj-xp48-7p7c

Moodle does not use the forceloginforprofiles setting for course-profiles access control

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4fm4-pcw7-99hg

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-m97f-x4mr-4x3q

Moodle vulnerable to Cross-Site Request Forgery

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p586-c547-p893

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79w6-7hhc-89m9

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jcrj-x36p-h9f6

Moodle Open Redirect in Calendar Set Page

0%
Низкий
больше 3 лет назад
github логотип
GHSA-62wv-866c-rh86

Moodle does not properly restrict comment capabilities

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться