Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-3r38-g3wv-x66q

около 4 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

EPSS: Низкий
github логотип

GHSA-3rqj-jchw-9cc7

около 4 лет назад

Moodle Authentication Bypass in Question-Bank

EPSS: Низкий
github логотип

GHSA-wq3g-p65w-h4pr

около 4 лет назад

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

EPSS: Низкий
github логотип

GHSA-mr97-gvvg-rhgh

около 4 лет назад

Moodle Exposes Sensitive User Information

EPSS: Низкий
github логотип

GHSA-8vqr-8829-g4x5

около 4 лет назад

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-gfh4-f3wf-9223

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

EPSS: Низкий
github логотип

GHSA-9qm6-cmrx-3j39

около 4 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

EPSS: Низкий
github логотип

GHSA-x786-87xq-6mh7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

EPSS: Низкий
github логотип

GHSA-h58j-h7qq-f2c2

около 4 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

EPSS: Низкий
github логотип

GHSA-4794-5xw8-8vrg

около 4 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-3r38-g3wv-x66q

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3rqj-jchw-9cc7

Moodle Authentication Bypass in Question-Bank

1%
Низкий
около 4 лет назад
github логотип
GHSA-wq3g-p65w-h4pr

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

2%
Низкий
около 4 лет назад
github логотип
GHSA-mr97-gvvg-rhgh

Moodle Exposes Sensitive User Information

1%
Низкий
около 4 лет назад
github логотип
GHSA-8vqr-8829-g4x5

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gfh4-f3wf-9223

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-9qm6-cmrx-3j39

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x786-87xq-6mh7

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

1%
Низкий
около 4 лет назад
github логотип
GHSA-h58j-h7qq-f2c2

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

0%
Низкий
около 4 лет назад
github логотип
GHSA-4794-5xw8-8vrg

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться