Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-r9pc-g29w-f86j

около 4 лет назад

Moodle sensitive information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r99q-hmqv-xw8w

около 2 лет назад

Moodle Authenticated LFI risk in some misconfigured shared hosting environments

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r867-v437-4rrm

около 4 лет назад

Moodle Cross-site request forgery (CSRF) vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r82w-3phg-qvr4

около 2 лет назад

Moodle uses the same key for QR login and auto-login

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r7cj-2ghq-wj88

около 4 лет назад

jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

EPSS: Низкий
github логотип

GHSA-r729-mx2r-j26j

около 4 лет назад

Moodle XSS Vulnerability

EPSS: Низкий
github логотип

GHSA-r6j4-gmpg-6x9f

около 4 лет назад

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-r4xr-m393-778m

больше 1 года назад

Moodle IDOR when accessing list of course badges

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r4vq-7rgp-99hx

около 4 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

EPSS: Низкий
github логотип

GHSA-r3fc-hx6q-g6cq

около 4 лет назад

Moodle allows attackers to discover student e-mail addresses

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r2wx-46gp-rp3h

около 2 лет назад

Moodle Improper Input Validation

EPSS: Низкий
github логотип

GHSA-r227-v24c-j96q

около 4 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qw6v-v9vc-qfvq

около 4 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

EPSS: Низкий
github логотип

GHSA-qv78-6gpp-hm68

6 месяцев назад

Moodle Open Redirect vulnerability

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-qv3v-qfq2-p7vh

около 4 лет назад

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.

EPSS: Низкий
github логотип

GHSA-qrqv-26gf-xgwh

больше 1 года назад

Moodle LFI vulnerability when restoring malformed block backups

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qrcj-6fjw-3h9h

около 4 лет назад

Moodle XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-qqvp-r28f-c3cv

около 4 лет назад

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

EPSS: Низкий
github логотип

GHSA-qqjv-mc2v-p7mc

около 4 лет назад

Moodle SSRF Vulnerability

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-qq3m-44fg-p6q8

около 4 лет назад

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r9pc-g29w-f86j

Moodle sensitive information disclosure

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-r99q-hmqv-xw8w

Moodle Authenticated LFI risk in some misconfigured shared hosting environments

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-r867-v437-4rrm

Moodle Cross-site request forgery (CSRF) vulnerability

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-r82w-3phg-qvr4

Moodle uses the same key for QR login and auto-login

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-r7cj-2ghq-wj88

jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-r729-mx2r-j26j

Moodle XSS Vulnerability

2%
Низкий
около 4 лет назад
github логотип
GHSA-r6j4-gmpg-6x9f

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-r4xr-m393-778m

Moodle IDOR when accessing list of course badges

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-r4vq-7rgp-99hx

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

2%
Низкий
около 4 лет назад
github логотип
GHSA-r3fc-hx6q-g6cq

Moodle allows attackers to discover student e-mail addresses

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-r2wx-46gp-rp3h

Moodle Improper Input Validation

1%
Низкий
около 2 лет назад
github логотип
GHSA-r227-v24c-j96q

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-qw6v-v9vc-qfvq

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

2%
Низкий
около 4 лет назад
github логотип
GHSA-qv78-6gpp-hm68

Moodle Open Redirect vulnerability

CVSS3: 3.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-qv3v-qfq2-p7vh

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qrqv-26gf-xgwh

Moodle LFI vulnerability when restoring malformed block backups

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-qrcj-6fjw-3h9h

Moodle XSS Vulnerability

CVSS3: 4.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-qqvp-r28f-c3cv

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

2%
Низкий
около 4 лет назад
github логотип
GHSA-qqjv-mc2v-p7mc

Moodle SSRF Vulnerability

CVSS3: 6.5
16%
Средний
около 4 лет назад
github логотип
GHSA-qq3m-44fg-p6q8

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу