Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-gr5q-9q5x-fx8h

около 4 лет назад

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

EPSS: Низкий
github логотип

GHSA-c2gc-3pq9-wq9x

около 4 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

EPSS: Низкий
github логотип

GHSA-xf8x-2jhx-xp6x

около 4 лет назад

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

EPSS: Низкий
github логотип

GHSA-hgw3-h5hf-vjv2

около 4 лет назад

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

EPSS: Низкий
github логотип

GHSA-mgqq-8x9v-jp4r

около 4 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

EPSS: Низкий
github логотип

GHSA-5hc2-8542-698w

около 4 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-6wq9-m5r8-4gq4

около 4 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

EPSS: Низкий
github логотип

GHSA-x8rw-c396-qjg7

около 4 лет назад

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

EPSS: Низкий
github логотип

GHSA-ffr2-q8c8-w5xj

около 4 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

EPSS: Низкий
github логотип

GHSA-r729-mx2r-j26j

около 4 лет назад

Moodle XSS Vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-gr5q-9q5x-fx8h

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

1%
Низкий
около 4 лет назад
github логотип
GHSA-c2gc-3pq9-wq9x

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xf8x-2jhx-xp6x

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

1%
Низкий
около 4 лет назад
github логотип
GHSA-hgw3-h5hf-vjv2

Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

2%
Низкий
около 4 лет назад
github логотип
GHSA-mgqq-8x9v-jp4r

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

2%
Низкий
около 4 лет назад
github логотип
GHSA-5hc2-8542-698w

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-6wq9-m5r8-4gq4

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

2%
Низкий
около 4 лет назад
github логотип
GHSA-x8rw-c396-qjg7

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

2%
Низкий
около 4 лет назад
github логотип
GHSA-ffr2-q8c8-w5xj

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

2%
Низкий
около 4 лет назад
github логотип
GHSA-r729-mx2r-j26j

Moodle XSS Vulnerability

2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться