Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
GHSA-qm6h-hvwq-4xp6
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
GHSA-7p9m-wjgf-7xr6
Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.
GHSA-4r4x-49qh-hfgv
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
GHSA-phqj-xp48-7p7c
Moodle does not use the forceloginforprofiles setting for course-profiles access control
GHSA-4fm4-pcw7-99hg
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.
GHSA-m97f-x4mr-4x3q
Moodle vulnerable to Cross-Site Request Forgery
GHSA-p586-c547-p893
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
GHSA-79w6-7hhc-89m9
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
GHSA-jcrj-x36p-h9f6
Moodle Open Redirect in Calendar Set Page
GHSA-62wv-866c-rh86
Moodle does not properly restrict comment capabilities
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-qm6h-hvwq-4xp6 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php. | 0% Низкий | больше 3 лет назад | ||
GHSA-7p9m-wjgf-7xr6 Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states. | 0% Низкий | больше 3 лет назад | ||
GHSA-4r4x-49qh-hfgv Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens. | 0% Низкий | больше 3 лет назад | ||
GHSA-phqj-xp48-7p7c Moodle does not use the forceloginforprofiles setting for course-profiles access control | 0% Низкий | больше 3 лет назад | ||
GHSA-4fm4-pcw7-99hg The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality. | 0% Низкий | больше 3 лет назад | ||
GHSA-m97f-x4mr-4x3q Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | больше 3 лет назад | ||
GHSA-p586-c547-p893 The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server. | 0% Низкий | больше 3 лет назад | ||
GHSA-79w6-7hhc-89m9 mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface. | 0% Низкий | больше 3 лет назад | ||
GHSA-jcrj-x36p-h9f6 Moodle Open Redirect in Calendar Set Page | 0% Низкий | больше 3 лет назад | ||
GHSA-62wv-866c-rh86 Moodle does not properly restrict comment capabilities | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу