Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2019-18210

больше 5 лет назад

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-18210

больше 5 лет назад

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows a ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3. ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is b ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14880

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-14880

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-14880

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 bef ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14879

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-14879

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-14879

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows a ...

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 ...

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3. ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to ...

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is b ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 bef ...

CVSS3: 9.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14879

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14879

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14879

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x ...

CVSS3: 5.4
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу