Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 499

github логотип

GHSA-gj2j-ppjq-9pjg

больше 3 лет назад

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mj85-3hqq-r6r9

больше 3 лет назад

Moodle Reflected XSS in mod_data advanced search

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wxqg-fg7v-mmc6

больше 3 лет назад

Moodle Authenticated Spelling Binary Remote Code Execution

EPSS: Средний
github логотип

GHSA-45rw-4r25-jvg7

больше 3 лет назад

Moodle Logged in users could view all calendar events

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qrcj-6fjw-3h9h

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-wm4w-8vc6-2j4h

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8wf8-rc66-c638

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

EPSS: Средний
github логотип

GHSA-7w7p-v23v-56qr

больше 3 лет назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

EPSS: Низкий
github логотип

GHSA-6w97-x9wf-g8mv

больше 3 лет назад

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

EPSS: Низкий
github логотип

GHSA-79vx-7whj-rvvr

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-gj2j-ppjq-9pjg

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mj85-3hqq-r6r9

Moodle Reflected XSS in mod_data advanced search

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wxqg-fg7v-mmc6

Moodle Authenticated Spelling Binary Remote Code Execution

64%
Средний
больше 3 лет назад
github логотип
GHSA-45rw-4r25-jvg7

Moodle Logged in users could view all calendar events

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-qrcj-6fjw-3h9h

Moodle XSS Vulnerability

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wm4w-8vc6-2j4h

Moodle XSS Vulnerability

CVSS3: 5.3
10%
Низкий
больше 3 лет назад
github логотип
GHSA-8wf8-rc66-c638

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

13%
Средний
больше 3 лет назад
github логотип
GHSA-7w7p-v23v-56qr

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-6w97-x9wf-g8mv

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-79vx-7whj-rvvr

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться