Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-3qg4-2fcm-c8f9
Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
GHSA-m2pf-4pf8-45j2
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
GHSA-fhgh-fjh9-vq62
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
GHSA-mx5g-3vxh-rgm8
Moodle vulnerable to XSS via bundled spikephpcoverage library
GHSA-j3x5-cwfj-pfcw
Moodle does not force password changes for autosubscribed users
GHSA-mw6p-49jf-9935
Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page
GHSA-6xqg-f34f-5fjx
Moodle vulnerable to Cross-site Scripting
GHSA-8vjj-wf73-w882
Moodle Incorrect Default Settings
GHSA-p269-r9cq-frhv
Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.
GHSA-qm6h-hvwq-4xp6
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-3qg4-2fcm-c8f9 Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members | 2% Низкий | около 4 лет назад | ||
GHSA-m2pf-4pf8-45j2 Moodle allows remote authenticated users to cause a denial of service (invalid database records) | 2% Низкий | около 4 лет назад | ||
GHSA-fhgh-fjh9-vq62 Moodle allows remote authenticated users to cause a denial of service (invalid database records) | 2% Низкий | около 4 лет назад | ||
GHSA-mx5g-3vxh-rgm8 Moodle vulnerable to XSS via bundled spikephpcoverage library | 4% Низкий | около 4 лет назад | ||
GHSA-j3x5-cwfj-pfcw Moodle does not force password changes for autosubscribed users | 2% Низкий | около 4 лет назад | ||
GHSA-mw6p-49jf-9935 Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page | 2% Низкий | около 4 лет назад | ||
GHSA-6xqg-f34f-5fjx Moodle vulnerable to Cross-site Scripting | 2% Низкий | около 4 лет назад | ||
GHSA-8vjj-wf73-w882 Moodle Incorrect Default Settings | 2% Низкий | около 4 лет назад | ||
GHSA-p269-r9cq-frhv Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page. | 1% Низкий | около 4 лет назад | ||
GHSA-qm6h-hvwq-4xp6 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу