Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-4pv6-rw85-g6wg

больше 3 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

EPSS: Низкий
github логотип

GHSA-8p86-57fx-w749

больше 3 лет назад

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

EPSS: Низкий
github логотип

GHSA-cc94-hwj3-rf65

больше 3 лет назад

Moodle's login_as feature leaks information from external repositories

EPSS: Низкий
github логотип

GHSA-893p-hqf6-mg67

больше 3 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

EPSS: Низкий
github логотип

GHSA-mxp2-wcjh-jf72

больше 3 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

EPSS: Низкий
github логотип

GHSA-wp3g-pr4h-q6vv

больше 3 лет назад

Moodle does not enforce capability requirements for reading blog comments

EPSS: Низкий
github логотип

GHSA-m63h-q4x3-6hwj

больше 3 лет назад

Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class

EPSS: Низкий
github логотип

GHSA-gr8w-hm62-xw58

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

EPSS: Низкий
github логотип

GHSA-x3x8-fjw6-hccx

больше 3 лет назад

Moodle does not consider "don't send" attributes during hub registration

EPSS: Низкий
github логотип

GHSA-w66h-c2vj-cm7f

больше 3 лет назад

Moodle Authentication Bypass in File Upload

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-4pv6-rw85-g6wg

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8p86-57fx-w749

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cc94-hwj3-rf65

Moodle's login_as feature leaks information from external repositories

0%
Низкий
больше 3 лет назад
github логотип
GHSA-893p-hqf6-mg67

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mxp2-wcjh-jf72

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wp3g-pr4h-q6vv

Moodle does not enforce capability requirements for reading blog comments

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m63h-q4x3-6hwj

Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class

1%
Низкий
больше 3 лет назад
github логотип
GHSA-gr8w-hm62-xw58

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x3x8-fjw6-hccx

Moodle does not consider "don't send" attributes during hub registration

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w66h-c2vj-cm7f

Moodle Authentication Bypass in File Upload

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться