Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 499

github логотип

GHSA-9r38-f9p6-3f7p

больше 3 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS: Низкий
github логотип

GHSA-ch68-5r37-p7c3

больше 3 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-h46g-v2m5-f7jh

больше 3 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

EPSS: Низкий
github логотип

GHSA-75c6-xqwr-v2r9

больше 3 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-pg89-qp74-vch2

больше 3 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

EPSS: Низкий
github логотип

GHSA-5rr5-fxhc-jv64

больше 3 лет назад

Moodle allows attackers to modify the visibility of a badge

EPSS: Низкий
github логотип

GHSA-6p3g-hw27-qh44

больше 3 лет назад

Moodle's time-validation implementation allows bypassing intended restrictions

EPSS: Низкий
github логотип

GHSA-267j-cwvg-j28c

больше 3 лет назад

Moodle attackers to modify grade metadata

EPSS: Низкий
github логотип

GHSA-c3vx-v4x8-x894

больше 3 лет назад

Moodle does not check for the moodle/course:viewhiddencourses capability

EPSS: Низкий
github логотип

GHSA-h75f-hjcr-cvh8

больше 3 лет назад

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9r38-f9p6-3f7p

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-ch68-5r37-p7c3

Moodle cross-site scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h46g-v2m5-f7jh

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-75c6-xqwr-v2r9

Moodle cross-site scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-pg89-qp74-vch2

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5rr5-fxhc-jv64

Moodle allows attackers to modify the visibility of a badge

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6p3g-hw27-qh44

Moodle's time-validation implementation allows bypassing intended restrictions

0%
Низкий
больше 3 лет назад
github логотип
GHSA-267j-cwvg-j28c

Moodle attackers to modify grade metadata

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c3vx-v4x8-x894

Moodle does not check for the moodle/course:viewhiddencourses capability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h75f-hjcr-cvh8

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться