Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-2hw8-qj3h-c7pq

больше 3 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

EPSS: Низкий
github логотип

GHSA-wjh9-wgjp-jmj6

больше 3 лет назад

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

EPSS: Низкий
github логотип

GHSA-9ww8-j8j2-3788

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-475h-wv64-r896

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

EPSS: Низкий
github логотип

GHSA-x5hj-47vv-53p8

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-64r3-582j-frqm

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-782m-5wvg-q53x

больше 3 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

EPSS: Низкий
github логотип

GHSA-cxp8-jjf5-6whc

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

EPSS: Низкий
github логотип

GHSA-vm9c-39jx-q45w

больше 3 лет назад

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

EPSS: Низкий
github логотип

GHSA-9r38-f9p6-3f7p

больше 3 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-2hw8-qj3h-c7pq

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wjh9-wgjp-jmj6

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9ww8-j8j2-3788

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-475h-wv64-r896

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x5hj-47vv-53p8

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-64r3-582j-frqm

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-782m-5wvg-q53x

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cxp8-jjf5-6whc

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-vm9c-39jx-q45w

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9r38-f9p6-3f7p

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться