Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2025-53021

около 1 года назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-53021

около 1 года назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2025-53021

около 1 года назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-cgvv-3455-824j

около 1 года назад

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2025-10235

около 1 года назад

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
EPSS: Низкий
redos логотип

ROS-20250822-06

11 месяцев назад

Уязвимость moodle

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
0%
Низкий
около 1 года назад
github логотип
GHSA-cgvv-3455-824j

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-10235

Уязвимость виртуальной обучающей среды Moodle, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя

CVSS3: 4.2
0%
Низкий
около 1 года назад
redos логотип
ROS-20250822-06

Уязвимость moodle

CVSS3: 4.2
0%
Низкий
11 месяцев назад

Уязвимостей на страницу