Количество 2 712
Количество 2 712
CVE-2021-36396
In Moodle, insufficient redirect handling made it possible to blindly ...
CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recur ...
CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibbole ...
CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetchin ...
CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetchin ...
CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sani ...
CVE-2021-32477
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
CVE-2021-32477
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
CVE-2021-32477
The last time a user accessed the mobile app is displayed on their pro ...
CVE-2021-32476
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-36396 In Moodle, insufficient redirect handling made it possible to blindly ... | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recur ... | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibbole ... | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | CVSS3: 9.8 | 52% Средний | больше 3 лет назад | |
CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | CVSS3: 9.8 | 52% Средний | больше 3 лет назад | |
CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetchin ... | CVSS3: 9.8 | 52% Средний | больше 3 лет назад | |
CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetchin ... | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sani ... | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32477 The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32477 The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32477 The last time a user accessed the mobile app is displayed on their pro ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-32476 A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу