Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

github логотип

GHSA-jcrj-x36p-h9f6

больше 3 лет назад

Moodle Open Redirect in Calendar Set Page

EPSS: Низкий
github логотип

GHSA-62wv-866c-rh86

больше 3 лет назад

Moodle does not properly restrict comment capabilities

EPSS: Низкий
github логотип

GHSA-g6cp-x8gq-65wc

больше 3 лет назад

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

EPSS: Низкий
github логотип

GHSA-gr5q-9q5x-fx8h

больше 3 лет назад

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

EPSS: Низкий
github логотип

GHSA-wxvp-8q8h-r6rr

больше 3 лет назад

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

EPSS: Низкий
github логотип

GHSA-8hxm-42v5-66hm

больше 3 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-xf8x-2jhx-xp6x

больше 3 лет назад

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

EPSS: Низкий
github логотип

GHSA-c2gc-3pq9-wq9x

больше 3 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

EPSS: Низкий
github логотип

GHSA-hgw3-h5hf-vjv2

больше 3 лет назад

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

EPSS: Низкий
github логотип

GHSA-x8rw-c396-qjg7

больше 3 лет назад

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-jcrj-x36p-h9f6

Moodle Open Redirect in Calendar Set Page

0%
Низкий
больше 3 лет назад
github логотип
GHSA-62wv-866c-rh86

Moodle does not properly restrict comment capabilities

1%
Низкий
больше 3 лет назад
github логотип
GHSA-g6cp-x8gq-65wc

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gr5q-9q5x-fx8h

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wxvp-8q8h-r6rr

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8hxm-42v5-66hm

Moodle vulnerable to Cross-Site Request Forgery

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xf8x-2jhx-xp6x

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c2gc-3pq9-wq9x

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hgw3-h5hf-vjv2

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x8rw-c396-qjg7

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться