Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 536
GHSA-jcrj-x36p-h9f6
Moodle Open Redirect in Calendar Set Page
GHSA-62wv-866c-rh86
Moodle does not properly restrict comment capabilities
GHSA-g6cp-x8gq-65wc
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
GHSA-gr5q-9q5x-fx8h
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
GHSA-wxvp-8q8h-r6rr
Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
GHSA-8hxm-42v5-66hm
Moodle vulnerable to Cross-Site Request Forgery
GHSA-xf8x-2jhx-xp6x
mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
GHSA-c2gc-3pq9-wq9x
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
GHSA-hgw3-h5hf-vjv2
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
GHSA-x8rw-c396-qjg7
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-jcrj-x36p-h9f6 Moodle Open Redirect in Calendar Set Page | 0% Низкий | больше 3 лет назад | ||
GHSA-62wv-866c-rh86 Moodle does not properly restrict comment capabilities | 1% Низкий | больше 3 лет назад | ||
GHSA-g6cp-x8gq-65wc Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL. | 0% Низкий | больше 3 лет назад | ||
GHSA-gr5q-9q5x-fx8h SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event. | 0% Низкий | больше 3 лет назад | ||
GHSA-wxvp-8q8h-r6rr Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory | 0% Низкий | больше 3 лет назад | ||
GHSA-8hxm-42v5-66hm Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | больше 3 лет назад | ||
GHSA-xf8x-2jhx-xp6x mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts. | 0% Низкий | больше 3 лет назад | ||
GHSA-c2gc-3pq9-wq9x The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request. | 0% Низкий | больше 3 лет назад | ||
GHSA-hgw3-h5hf-vjv2 Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface. | 0% Низкий | больше 3 лет назад | ||
GHSA-x8rw-c396-qjg7 The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу