Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

ubuntu логотип

CVE-2022-30597

больше 3 лет назад

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-30600

больше 3 лет назад

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk alloca ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-30596

больше 3 лет назад

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-h289-v8rh-2wvj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

EPSS: Низкий
github логотип

GHSA-xf6r-r485-49mr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

EPSS: Низкий
github логотип

GHSA-5488-2xmq-hwfh

больше 3 лет назад

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

EPSS: Низкий
github логотип

GHSA-hxvf-5p7c-7g55

больше 3 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

EPSS: Низкий
github логотип

GHSA-vg4g-6rhx-p7rr

больше 3 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-30597

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-30600

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk alloca ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h289-v8rh-2wvj

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xf6r-r485-49mr

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-5488-2xmq-hwfh

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hxvf-5p7c-7g55

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-vg4g-6rhx-p7rr

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться