Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
GHSA-hgw3-h5hf-vjv2
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
GHSA-6wq9-m5r8-4gq4
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
GHSA-x8rw-c396-qjg7
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
GHSA-8fqh-rfgp-g35q
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
GHSA-r729-mx2r-j26j
Moodle XSS Vulnerability
GHSA-ffr2-q8c8-w5xj
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
GHSA-hp4v-c3h7-rwmx
mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.
GHSA-hxmp-8f47-x9fc
Moodle Open Redirect Via Error Messages
GHSA-jcrj-gmr6-p5j8
Moodle Allows Modification of Constants
GHSA-45ch-hxgr-vx8j
phpCAS client library and Moodle Cross-site Scripting vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-hgw3-h5hf-vjv2 Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface. | 0% Низкий | больше 3 лет назад | ||
GHSA-6wq9-m5r8-4gq4 message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing. | 0% Низкий | больше 3 лет назад | ||
GHSA-x8rw-c396-qjg7 The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site. | 0% Низкий | больше 3 лет назад | ||
GHSA-8fqh-rfgp-g35q mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-r729-mx2r-j26j Moodle XSS Vulnerability | 0% Низкий | больше 3 лет назад | ||
GHSA-ffr2-q8c8-w5xj login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network. | 0% Низкий | больше 3 лет назад | ||
GHSA-hp4v-c3h7-rwmx mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-hxmp-8f47-x9fc Moodle Open Redirect Via Error Messages | 0% Низкий | больше 3 лет назад | ||
GHSA-jcrj-gmr6-p5j8 Moodle Allows Modification of Constants | 0% Низкий | больше 3 лет назад | ||
GHSA-45ch-hxgr-vx8j phpCAS client library and Moodle Cross-site Scripting vulnerability | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу