Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

debian логотип

CVE-2021-20187

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2021-20186

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-20186

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-20186

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-20185

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-20185

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-20185

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-20184

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-20184

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-20184

почти 5 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a i ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-20183

почти 5 лет назад

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-20183

почти 5 лет назад

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-20183

почти 5 лет назад

It was found in Moodle before version 3.10.1 that some search inputs w ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2020-25703

около 5 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25703

около 5 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25703

около 5 лет назад

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-25702

около 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25702

около 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25702

около 5 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25701

около 5 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-20187

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 7.2
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-20186

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20186

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-20186

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a i ...

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs w ...

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
0%
Низкий
около 5 лет назад

Уязвимостей на страницу