Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-c6g7-c2cg-grhj
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.
GHSA-m55g-vpgh-vw7c
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
GHSA-jj3p-6mw3-6qmm
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").
GHSA-995f-r3qg-j3mx
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.
GHSA-grj4-g57c-9xmv
Moodle Bypass email verification secret when confirming account registration
GHSA-2m72-m5cw-3g9h
Missing permission check in Moodle
GHSA-h7h6-fwpv-ggvx
Moodle contains Stored XSS via ID number user profile field
GHSA-xhfx-rm8q-c3xv
Moodle Vulnerable to Reflected Cross-site Scripting
GHSA-c3j6-33r4-89q3
Moodle Client side denial of service via personal message
GHSA-mm73-86f9-5x5c
Moodle Grade information disclosure in grade's external fetch functions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-c6g7-c2cg-grhj A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role. | 1% Низкий | около 4 лет назад | ||
GHSA-m55g-vpgh-vw7c A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-jj3p-6mw3-6qmm A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app"). | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-995f-r3qg-j3mx A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-grj4-g57c-9xmv Moodle Bypass email verification secret when confirming account registration | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-2m72-m5cw-3g9h Missing permission check in Moodle | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-h7h6-fwpv-ggvx Moodle contains Stored XSS via ID number user profile field | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-xhfx-rm8q-c3xv Moodle Vulnerable to Reflected Cross-site Scripting | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-c3j6-33r4-89q3 Moodle Client side denial of service via personal message | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-mm73-86f9-5x5c Moodle Grade information disclosure in grade's external fetch functions | CVSS3: 4.3 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу