Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 577

github логотип

GHSA-475h-wv64-r896

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

EPSS: Низкий
github логотип

GHSA-vm9c-39jx-q45w

больше 3 лет назад

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

EPSS: Низкий
github логотип

GHSA-x5hj-47vv-53p8

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-782m-5wvg-q53x

больше 3 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

EPSS: Низкий
github логотип

GHSA-64r3-582j-frqm

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-3f43-8vw5-xcf9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

EPSS: Низкий
github логотип

GHSA-6ggr-h9vf-pg47

больше 3 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

EPSS: Низкий
github логотип

GHSA-gxf9-5xr3-34cc

больше 3 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

EPSS: Низкий
github логотип

GHSA-9r38-f9p6-3f7p

больше 3 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS: Низкий
github логотип

GHSA-h46g-v2m5-f7jh

больше 3 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-475h-wv64-r896

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-vm9c-39jx-q45w

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x5hj-47vv-53p8

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-782m-5wvg-q53x

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-64r3-582j-frqm

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f43-8vw5-xcf9

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6ggr-h9vf-pg47

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gxf9-5xr3-34cc

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9r38-f9p6-3f7p

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h46g-v2m5-f7jh

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться