Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 536

github логотип

GHSA-mgqq-8x9v-jp4r

больше 3 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

EPSS: Низкий
github логотип

GHSA-6wq9-m5r8-4gq4

больше 3 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

EPSS: Низкий
github логотип

GHSA-5hc2-8542-698w

больше 3 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-ffr2-q8c8-w5xj

больше 3 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

EPSS: Низкий
github логотип

GHSA-r729-mx2r-j26j

больше 3 лет назад

Moodle XSS Vulnerability

EPSS: Низкий
github логотип

GHSA-8fqh-rfgp-g35q

больше 3 лет назад

mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-hp4v-c3h7-rwmx

больше 3 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-hxmp-8f47-x9fc

больше 3 лет назад

Moodle Open Redirect Via Error Messages

EPSS: Низкий
github логотип

GHSA-jcrj-gmr6-p5j8

больше 3 лет назад

Moodle Allows Modification of Constants

EPSS: Низкий
github логотип

GHSA-3jfw-v39g-268j

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mgqq-8x9v-jp4r

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-6wq9-m5r8-4gq4

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5hc2-8542-698w

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-ffr2-q8c8-w5xj

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r729-mx2r-j26j

Moodle XSS Vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8fqh-rfgp-g35q

mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hp4v-c3h7-rwmx

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hxmp-8f47-x9fc

Moodle Open Redirect Via Error Messages

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jcrj-gmr6-p5j8

Moodle Allows Modification of Constants

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jfw-v39g-268j

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться