Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-8fqh-rfgp-g35q
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
GHSA-hp4v-c3h7-rwmx
mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.
GHSA-jcrj-gmr6-p5j8
Moodle Allows Modification of Constants
GHSA-hxmp-8f47-x9fc
Moodle Open Redirect Via Error Messages
GHSA-m3xp-4hf3-qfpp
Moodle allows remote attackers to obtain sensitive information
GHSA-86v9-gqh9-8268
Moodle vulnerable to Cross-site Scripting
GHSA-6656-6qwx-4c2m
Moodle XSS In Tag Autocomplete functionality
GHSA-45ch-hxgr-vx8j
phpCAS client library and Moodle Cross-site Scripting vulnerability
GHSA-qq3m-44fg-p6q8
Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.
GHSA-9xp2-5fr9-7mwm
Moodle vulnerable to SQL injection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-8fqh-rfgp-g35q mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-hp4v-c3h7-rwmx mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate. | 1% Низкий | около 4 лет назад | ||
GHSA-jcrj-gmr6-p5j8 Moodle Allows Modification of Constants | 2% Низкий | около 4 лет назад | ||
GHSA-hxmp-8f47-x9fc Moodle Open Redirect Via Error Messages | 2% Низкий | около 4 лет назад | ||
GHSA-m3xp-4hf3-qfpp Moodle allows remote attackers to obtain sensitive information | 2% Низкий | около 4 лет назад | ||
GHSA-86v9-gqh9-8268 Moodle vulnerable to Cross-site Scripting | 2% Низкий | около 4 лет назад | ||
GHSA-6656-6qwx-4c2m Moodle XSS In Tag Autocomplete functionality | 2% Низкий | около 4 лет назад | ||
GHSA-45ch-hxgr-vx8j phpCAS client library and Moodle Cross-site Scripting vulnerability | 2% Низкий | около 4 лет назад | ||
GHSA-qq3m-44fg-p6q8 Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role. | 2% Низкий | около 4 лет назад | ||
GHSA-9xp2-5fr9-7mwm Moodle vulnerable to SQL injection | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу