Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

github логотип

GHSA-99w2-c54x-whrx

больше 3 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

EPSS: Низкий
github логотип

GHSA-9qm6-cmrx-3j39

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

EPSS: Низкий
github логотип

GHSA-3r38-g3wv-x66q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

EPSS: Низкий
github логотип

GHSA-74j7-5pxr-x457

больше 3 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

EPSS: Низкий
github логотип

GHSA-4794-5xw8-8vrg

больше 3 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

EPSS: Низкий
github логотип

GHSA-h58j-h7qq-f2c2

больше 3 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

EPSS: Низкий
github логотип

GHSA-4w8m-96v9-2c86

больше 3 лет назад

Moodle CRLF Injection Vulnerability in Calendar Component

EPSS: Низкий
github логотип

GHSA-9fh3-hj27-mwr8

больше 3 лет назад

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

EPSS: Низкий
github логотип

GHSA-3gm8-32vv-q8mp

больше 3 лет назад

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

EPSS: Низкий
github логотип

GHSA-72gv-qqrp-h9qg

больше 3 лет назад

Moodle Users Can Bypass Deleted Status

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-99w2-c54x-whrx

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9qm6-cmrx-3j39

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r38-g3wv-x66q

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-74j7-5pxr-x457

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4794-5xw8-8vrg

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-h58j-h7qq-f2c2

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4w8m-96v9-2c86

Moodle CRLF Injection Vulnerability in Calendar Component

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9fh3-hj27-mwr8

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gm8-32vv-q8mp

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

0%
Низкий
больше 3 лет назад
github логотип
GHSA-72gv-qqrp-h9qg

Moodle Users Can Bypass Deleted Status

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться