Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2019-10188

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teache ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-10187

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-10187

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-10187

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-10186

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-10186

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-10186

почти 6 лет назад

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sess ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10154

около 6 лет назад

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10154

около 6 лет назад

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10154

около 6 лет назад

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service f ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10134

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2019-10134

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2019-10134

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2019-10133

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2019-10133

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2019-10133

около 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2018-16854

больше 6 лет назад

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-16854

больше 6 лет назад

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-16854

больше 6 лет назад

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-14631

почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2019-10188

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teache ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-10187

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-10187

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10187

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users ...

CVSS3: 4.3
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-10186

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-10186

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10186

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sess ...

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service f ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10134

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10134

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10134

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.7
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

CVSS3: 3.1
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2018-16854

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-16854

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-16854

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to ...

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-14631

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.

CVSS3: 8.8
1%
Низкий
почти 7 лет назад

Уязвимостей на страницу