Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-cj27-r58c-6p6v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

EPSS: Низкий
github логотип

GHSA-g5p6-83fw-2xvf

больше 3 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

EPSS: Низкий
github логотип

GHSA-7q33-5wgv-9752

больше 3 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

EPSS: Низкий
github логотип

GHSA-4jc7-gpxx-gg52

больше 3 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

EPSS: Низкий
github логотип

GHSA-9p54-pc88-36c4

больше 3 лет назад

Moodle does not properly restrict access to category and course data

EPSS: Низкий
github логотип

GHSA-h6px-pvfh-q2jv

больше 3 лет назад

Moodle vulnerable to Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-g6cp-x8gq-65wc

больше 3 лет назад

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

EPSS: Низкий
github логотип

GHSA-6rm3-82c3-gjr8

больше 3 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

EPSS: Низкий
github логотип

GHSA-wxvp-8q8h-r6rr

больше 3 лет назад

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

EPSS: Низкий
github логотип

GHSA-8hxm-42v5-66hm

больше 3 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-cj27-r58c-6p6v

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g5p6-83fw-2xvf

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7q33-5wgv-9752

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4jc7-gpxx-gg52

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9p54-pc88-36c4

Moodle does not properly restrict access to category and course data

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h6px-pvfh-q2jv

Moodle vulnerable to Cross-Site Scripting

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g6cp-x8gq-65wc

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6rm3-82c3-gjr8

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wxvp-8q8h-r6rr

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8hxm-42v5-66hm

Moodle vulnerable to Cross-Site Request Forgery

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться