Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

github логотип

GHSA-8p2c-fgqv-ch4v

больше 3 лет назад

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.

EPSS: Низкий
github логотип

GHSA-4xjc-8h53-m2ww

больше 3 лет назад

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

EPSS: Низкий
github логотип

GHSA-3w4p-mc7m-x3qf

больше 3 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

EPSS: Низкий
github логотип

GHSA-59w4-qq7r-6mf4

больше 3 лет назад

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

EPSS: Низкий
github логотип

GHSA-9ww8-j8j2-3788

больше 3 лет назад

YUI Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-wjh9-wgjp-jmj6

больше 3 лет назад

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

EPSS: Низкий
github логотип

GHSA-2hw8-qj3h-c7pq

больше 3 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

EPSS: Низкий
github логотип

GHSA-cr78-rphw-w73p

больше 3 лет назад

Moodle Arbitrary File Read via Backup Functionality

EPSS: Низкий
github логотип

GHSA-vm9c-39jx-q45w

больше 3 лет назад

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

EPSS: Низкий
github логотип

GHSA-782m-5wvg-q53x

больше 3 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-8p2c-fgqv-ch4v

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4xjc-8h53-m2ww

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w4p-mc7m-x3qf

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-59w4-qq7r-6mf4

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9ww8-j8j2-3788

YUI Cross-site Scripting (XSS) vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wjh9-wgjp-jmj6

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw8-qj3h-c7pq

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cr78-rphw-w73p

Moodle Arbitrary File Read via Backup Functionality

0%
Низкий
больше 3 лет назад
github логотип
GHSA-vm9c-39jx-q45w

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

0%
Низкий
больше 3 лет назад
github логотип
GHSA-782m-5wvg-q53x

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться