Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-phqj-xp48-7p7c

около 4 лет назад

Moodle does not use the forceloginforprofiles setting for course-profiles access control

EPSS: Низкий
github логотип

GHSA-m97f-x4mr-4x3q

около 4 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-7p9m-wjgf-7xr6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

EPSS: Низкий
github логотип

GHSA-6q96-wmxp-mc79

около 4 лет назад

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

EPSS: Низкий
github логотип

GHSA-4r4x-49qh-hfgv

около 4 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

EPSS: Низкий
github логотип

GHSA-4fm4-pcw7-99hg

около 4 лет назад

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

EPSS: Низкий
github логотип

GHSA-p586-c547-p893

около 4 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

EPSS: Низкий
github логотип

GHSA-9p54-pc88-36c4

около 4 лет назад

Moodle does not properly restrict access to category and course data

EPSS: Низкий
github логотип

GHSA-7q33-5wgv-9752

около 4 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

EPSS: Низкий
github логотип

GHSA-g5p6-83fw-2xvf

около 4 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-phqj-xp48-7p7c

Moodle does not use the forceloginforprofiles setting for course-profiles access control

1%
Низкий
около 4 лет назад
github логотип
GHSA-m97f-x4mr-4x3q

Moodle vulnerable to Cross-Site Request Forgery

1%
Низкий
около 4 лет назад
github логотип
GHSA-7p9m-wjgf-7xr6

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

2%
Низкий
около 4 лет назад
github логотип
GHSA-6q96-wmxp-mc79

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4r4x-49qh-hfgv

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4fm4-pcw7-99hg

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p586-c547-p893

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9p54-pc88-36c4

Moodle does not properly restrict access to category and course data

2%
Низкий
около 4 лет назад
github логотип
GHSA-7q33-5wgv-9752

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5p6-83fw-2xvf

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться