Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
GHSA-phqj-xp48-7p7c
Moodle does not use the forceloginforprofiles setting for course-profiles access control
GHSA-6q96-wmxp-mc79
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
GHSA-cj27-r58c-6p6v
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
GHSA-79w6-7hhc-89m9
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
GHSA-7q33-5wgv-9752
The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.
GHSA-g5p6-83fw-2xvf
lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.
GHSA-jcrj-x36p-h9f6
Moodle Open Redirect in Calendar Set Page
GHSA-g6cp-x8gq-65wc
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
GHSA-4jc7-gpxx-gg52
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
GHSA-h6px-pvfh-q2jv
Moodle vulnerable to Cross-Site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-phqj-xp48-7p7c Moodle does not use the forceloginforprofiles setting for course-profiles access control | 0% Низкий | больше 3 лет назад | ||
GHSA-6q96-wmxp-mc79 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action. | 0% Низкий | больше 3 лет назад | ||
GHSA-cj27-r58c-6p6v Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-79w6-7hhc-89m9 mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface. | 0% Низкий | больше 3 лет назад | ||
GHSA-7q33-5wgv-9752 The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment. | 0% Низкий | больше 3 лет назад | ||
GHSA-g5p6-83fw-2xvf lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature. | 0% Низкий | больше 3 лет назад | ||
GHSA-jcrj-x36p-h9f6 Moodle Open Redirect in Calendar Set Page | 0% Низкий | больше 3 лет назад | ||
GHSA-g6cp-x8gq-65wc Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL. | 0% Низкий | больше 3 лет назад | ||
GHSA-4jc7-gpxx-gg52 The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation. | 0% Низкий | больше 3 лет назад | ||
GHSA-h6px-pvfh-q2jv Moodle vulnerable to Cross-Site Scripting | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу