Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

github логотип

GHSA-7p9m-wjgf-7xr6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

EPSS: Низкий
github логотип

GHSA-4r4x-49qh-hfgv

больше 3 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

EPSS: Низкий
github логотип

GHSA-h6px-pvfh-q2jv

больше 3 лет назад

Moodle vulnerable to Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-79w6-7hhc-89m9

больше 3 лет назад

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

EPSS: Низкий
github логотип

GHSA-g5p6-83fw-2xvf

больше 3 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

EPSS: Низкий
github логотип

GHSA-6rm3-82c3-gjr8

больше 3 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

EPSS: Низкий
github логотип

GHSA-7q33-5wgv-9752

больше 3 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

EPSS: Низкий
github логотип

GHSA-9p54-pc88-36c4

больше 3 лет назад

Moodle does not properly restrict access to category and course data

EPSS: Низкий
github логотип

GHSA-4jc7-gpxx-gg52

больше 3 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

EPSS: Низкий
github логотип

GHSA-cj27-r58c-6p6v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-7p9m-wjgf-7xr6

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4r4x-49qh-hfgv

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h6px-pvfh-q2jv

Moodle vulnerable to Cross-Site Scripting

0%
Низкий
больше 3 лет назад
github логотип
GHSA-79w6-7hhc-89m9

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g5p6-83fw-2xvf

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6rm3-82c3-gjr8

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7q33-5wgv-9752

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9p54-pc88-36c4

Moodle does not properly restrict access to category and course data

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4jc7-gpxx-gg52

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cj27-r58c-6p6v

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться