Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

ubuntu логотип

CVE-2020-25628

около 5 лет назад

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25628

около 5 лет назад

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25628

около 5 лет назад

The filter in the tag manager required extra sanitizing to prevent a r ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25627

около 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25627

около 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25627

около 5 лет назад

The moodlenetprofile user profile field required extra sanitizing to p ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-1756

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2020-1756

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2020-1756

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input es ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2020-1755

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-1755

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-1755

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For heade ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-1754

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-1754

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-1754

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the gra ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2020-1692

почти 6 лет назад

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2020-1692

почти 6 лет назад

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2020-1692

почти 6 лет назад

Moodle before version 3.7.2 is vulnerable to information exposure of s ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2020-1691

больше 3 лет назад

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2020-1691

больше 3 лет назад

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a r ...

CVSS3: 6.1
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
5%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
5%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to p ...

CVSS3: 6.1
5%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-1756

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2020-1756

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2020-1756

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input es ...

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-1755

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2020-1755

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2020-1755

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For heade ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-1754

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2020-1754

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2020-1754

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the gra ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-1692

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

CVSS3: 8.1
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-1692

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

CVSS3: 8.1
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-1692

Moodle before version 3.7.2 is vulnerable to information exposure of s ...

CVSS3: 8.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу