Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

github логотип

GHSA-ghqg-3wq5-437q

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

EPSS: Низкий
github логотип

GHSA-h2rg-p9qr-pqcr

больше 3 лет назад

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

EPSS: Низкий
github логотип

GHSA-xfgq-37vh-892j

больше 3 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-w2pj-r8m3-r4jc

больше 3 лет назад

Moodle Information Disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hw6-6rgf-726v

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v33x-q8gh-4x42

больше 3 лет назад

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-grvw-qq2j-r898

больше 3 лет назад

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mm9q-3847-m48x

больше 3 лет назад

Moodle allows attackers to enter additional answer attempts

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-r227-v24c-j96q

больше 3 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6922-5v25-p8jg

больше 3 лет назад

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-ghqg-3wq5-437q

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h2rg-p9qr-pqcr

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xfgq-37vh-892j

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w2pj-r8m3-r4jc

Moodle Information Disclosure

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw6-6rgf-726v

Moodle XSS Vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-v33x-q8gh-4x42

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-grvw-qq2j-r898

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mm9q-3847-m48x

Moodle allows attackers to enter additional answer attempts

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-r227-v24c-j96q

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6922-5v25-p8jg

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться