Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
GHSA-4pv6-rw85-g6wg
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
GHSA-8p86-57fx-w749
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
GHSA-cc94-hwj3-rf65
Moodle's login_as feature leaks information from external repositories
GHSA-893p-hqf6-mg67
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
GHSA-mxp2-wcjh-jf72
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
GHSA-wp3g-pr4h-q6vv
Moodle does not enforce capability requirements for reading blog comments
GHSA-m63h-q4x3-6hwj
Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
GHSA-gr8w-hm62-xw58
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
GHSA-x3x8-fjw6-hccx
Moodle does not consider "don't send" attributes during hub registration
GHSA-w66h-c2vj-cm7f
Moodle Authentication Bypass in File Upload
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-4pv6-rw85-g6wg theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. | 0% Низкий | больше 3 лет назад | ||
GHSA-8p86-57fx-w749 Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities. | 0% Низкий | больше 3 лет назад | ||
GHSA-cc94-hwj3-rf65 Moodle's login_as feature leaks information from external repositories | 0% Низкий | больше 3 лет назад | ||
GHSA-893p-hqf6-mg67 lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users. | 0% Низкий | больше 3 лет назад | ||
GHSA-mxp2-wcjh-jf72 The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record. | 0% Низкий | больше 3 лет назад | ||
GHSA-wp3g-pr4h-q6vv Moodle does not enforce capability requirements for reading blog comments | 1% Низкий | больше 3 лет назад | ||
GHSA-m63h-q4x3-6hwj Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class | 1% Низкий | больше 3 лет назад | ||
GHSA-gr8w-hm62-xw58 Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365. | 0% Низкий | больше 3 лет назад | ||
GHSA-x3x8-fjw6-hccx Moodle does not consider "don't send" attributes during hub registration | 0% Низкий | больше 3 лет назад | ||
GHSA-w66h-c2vj-cm7f Moodle Authentication Bypass in File Upload | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу