Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
GHSA-cj27-r58c-6p6v
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
GHSA-g5p6-83fw-2xvf
lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.
GHSA-7q33-5wgv-9752
The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.
GHSA-4jc7-gpxx-gg52
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
GHSA-9p54-pc88-36c4
Moodle does not properly restrict access to category and course data
GHSA-h6px-pvfh-q2jv
Moodle vulnerable to Cross-Site Scripting
GHSA-g6cp-x8gq-65wc
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
GHSA-6rm3-82c3-gjr8
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
GHSA-wxvp-8q8h-r6rr
Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
GHSA-8hxm-42v5-66hm
Moodle vulnerable to Cross-Site Request Forgery
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-cj27-r58c-6p6v Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-g5p6-83fw-2xvf lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature. | 0% Низкий | больше 3 лет назад | ||
GHSA-7q33-5wgv-9752 The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment. | 0% Низкий | больше 3 лет назад | ||
GHSA-4jc7-gpxx-gg52 The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation. | 0% Низкий | больше 3 лет назад | ||
GHSA-9p54-pc88-36c4 Moodle does not properly restrict access to category and course data | 0% Низкий | больше 3 лет назад | ||
GHSA-h6px-pvfh-q2jv Moodle vulnerable to Cross-Site Scripting | 0% Низкий | больше 3 лет назад | ||
GHSA-g6cp-x8gq-65wc Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL. | 0% Низкий | больше 3 лет назад | ||
GHSA-6rm3-82c3-gjr8 lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role. | 0% Низкий | больше 3 лет назад | ||
GHSA-wxvp-8q8h-r6rr Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory | 0% Низкий | больше 3 лет назад | ||
GHSA-8hxm-42v5-66hm Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу