Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 541

Количество 2 541

ubuntu логотип

CVE-2019-3808

больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-3808

больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-3808

больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-18210

больше 5 лет назад

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-18210

больше 5 лет назад

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-18210

больше 5 лет назад

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows a ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14884

больше 5 лет назад

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-14883

больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3. ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14882

больше 5 лет назад

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-14881

больше 5 лет назад

A vulnerability was found in moodle 3.7 before 3.7.3, where there is b ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14880

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-14880

больше 5 лет назад

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-3808

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-3808

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-3808

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows a ...

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 ...

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3. ...

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to ...

CVSS3: 6.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is b ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

CVSS3: 9.1
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу