Количество 2 469
Количество 2 469
GHSA-xxp4-mf4h-6cwm
Moodle vulnerable to Server Side Request Forgery
GHSA-xv72-6pgh-cjj8
Moodle stored-XSS vulnerability in some "social" user profile fields
GHSA-xr24-jp5c-6c4v
Moodle reveals absolute path in exception message
GHSA-xqhh-253w-4q5f
Moodle Cross-site Scripting (XSS)
GHSA-xpfv-89vg-r562
Cross Site Request Forgery in Moodle
GHSA-xp2f-9mx3-3c6p
Moodle PostScript Code Injection
GHSA-xmwv-mqh8-4xgw
Moodle allows remote attackers to read arbitrary files
GHSA-xjx9-7c29-pwmm
Moodle Improper Privilege Management
GHSA-xjr3-fwp9-9g96
Moodle Cross-Site Request Forgery (CSRF)
GHSA-xj5f-qv37-r9jc
Moodle Login CSRF vulnerability in login form
GHSA-xhq3-455r-xv44
Moodle SQL injection via user preferences
GHSA-xhg2-vjrc-jqj8
repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.
GHSA-xhfx-rm8q-c3xv
Moodle Vulnerable to Reflected Cross-site Scripting
GHSA-xhfw-wjjc-4j5h
Moodle Cross-site Scripting
GHSA-xh2j-q4mc-v522
Moodle calculated question type allows remote code execution by Question authors
GHSA-xfv7-h2qg-rjm7
Moodle Lesson activity password bypass through PHP loose comparison
GHSA-xfgq-37vh-892j
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
GHSA-xf8x-2jhx-xp6x
mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
GHSA-xc4m-425c-6frg
auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.
GHSA-x92j-j6qp-c93p
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-xxp4-mf4h-6cwm Moodle vulnerable to Server Side Request Forgery | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-xv72-6pgh-cjj8 Moodle stored-XSS vulnerability in some "social" user profile fields | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-xr24-jp5c-6c4v Moodle reveals absolute path in exception message | 0% Низкий | около 3 лет назад | ||
GHSA-xqhh-253w-4q5f Moodle Cross-site Scripting (XSS) | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-xpfv-89vg-r562 Cross Site Request Forgery in Moodle | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xp2f-9mx3-3c6p Moodle PostScript Code Injection | CVSS3: 9.8 | 4% Низкий | почти 3 года назад | |
GHSA-xmwv-mqh8-4xgw Moodle allows remote attackers to read arbitrary files | 0% Низкий | около 3 лет назад | ||
GHSA-xjx9-7c29-pwmm Moodle Improper Privilege Management | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-xjr3-fwp9-9g96 Moodle Cross-Site Request Forgery (CSRF) | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xj5f-qv37-r9jc Moodle Login CSRF vulnerability in login form | CVSS3: 8.8 | 2% Низкий | около 3 лет назад | |
GHSA-xhq3-455r-xv44 Moodle SQL injection via user preferences | CVSS3: 9.8 | 2% Низкий | около 3 лет назад | |
GHSA-xhg2-vjrc-jqj8 repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value. | 0% Низкий | около 3 лет назад | ||
GHSA-xhfx-rm8q-c3xv Moodle Vulnerable to Reflected Cross-site Scripting | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
GHSA-xhfw-wjjc-4j5h Moodle Cross-site Scripting | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-xh2j-q4mc-v522 Moodle calculated question type allows remote code execution by Question authors | CVSS3: 8.8 | 63% Средний | около 3 лет назад | |
GHSA-xfv7-h2qg-rjm7 Moodle Lesson activity password bypass through PHP loose comparison | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
GHSA-xfgq-37vh-892j Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | CVSS3: 6.8 | 1% Низкий | около 3 лет назад | |
GHSA-xf8x-2jhx-xp6x mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts. | 0% Низкий | около 3 лет назад | ||
GHSA-xc4m-425c-6frg auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network. | 0% Низкий | около 3 лет назад | ||
GHSA-x92j-j6qp-c93p In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу