Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

github логотип

GHSA-62wv-866c-rh86

больше 3 лет назад

Moodle does not properly restrict comment capabilities

EPSS: Низкий
github логотип

GHSA-9p54-pc88-36c4

больше 3 лет назад

Moodle does not properly restrict access to category and course data

EPSS: Низкий
github логотип

GHSA-6rm3-82c3-gjr8

больше 3 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

EPSS: Низкий
github логотип

GHSA-gr5q-9q5x-fx8h

больше 3 лет назад

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

EPSS: Низкий
github логотип

GHSA-8hxm-42v5-66hm

больше 3 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-wxvp-8q8h-r6rr

больше 3 лет назад

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

EPSS: Низкий
github логотип

GHSA-xf8x-2jhx-xp6x

больше 3 лет назад

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

EPSS: Низкий
github логотип

GHSA-c2gc-3pq9-wq9x

больше 3 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

EPSS: Низкий
github логотип

GHSA-mgqq-8x9v-jp4r

больше 3 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

EPSS: Низкий
github логотип

GHSA-6wq9-m5r8-4gq4

больше 3 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-62wv-866c-rh86

Moodle does not properly restrict comment capabilities

1%
Низкий
больше 3 лет назад
github логотип
GHSA-9p54-pc88-36c4

Moodle does not properly restrict access to category and course data

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6rm3-82c3-gjr8

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gr5q-9q5x-fx8h

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8hxm-42v5-66hm

Moodle vulnerable to Cross-Site Request Forgery

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wxvp-8q8h-r6rr

Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xf8x-2jhx-xp6x

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c2gc-3pq9-wq9x

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mgqq-8x9v-jp4r

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-6wq9-m5r8-4gq4

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться