Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
GHSA-62wv-866c-rh86
Moodle does not properly restrict comment capabilities
GHSA-9p54-pc88-36c4
Moodle does not properly restrict access to category and course data
GHSA-6rm3-82c3-gjr8
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
GHSA-gr5q-9q5x-fx8h
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
GHSA-8hxm-42v5-66hm
Moodle vulnerable to Cross-Site Request Forgery
GHSA-wxvp-8q8h-r6rr
Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
GHSA-xf8x-2jhx-xp6x
mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
GHSA-c2gc-3pq9-wq9x
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
GHSA-mgqq-8x9v-jp4r
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
GHSA-6wq9-m5r8-4gq4
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-62wv-866c-rh86 Moodle does not properly restrict comment capabilities | 1% Низкий | больше 3 лет назад | ||
GHSA-9p54-pc88-36c4 Moodle does not properly restrict access to category and course data | 0% Низкий | больше 3 лет назад | ||
GHSA-6rm3-82c3-gjr8 lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role. | 0% Низкий | больше 3 лет назад | ||
GHSA-gr5q-9q5x-fx8h SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event. | 0% Низкий | больше 3 лет назад | ||
GHSA-8hxm-42v5-66hm Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | больше 3 лет назад | ||
GHSA-wxvp-8q8h-r6rr Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory | 0% Низкий | больше 3 лет назад | ||
GHSA-xf8x-2jhx-xp6x mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts. | 0% Низкий | больше 3 лет назад | ||
GHSA-c2gc-3pq9-wq9x The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request. | 0% Низкий | больше 3 лет назад | ||
GHSA-mgqq-8x9v-jp4r lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords. | 1% Низкий | больше 3 лет назад | ||
GHSA-6wq9-m5r8-4gq4 message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу