Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 647

Количество 2 647

nvd логотип

CVE-2019-3851

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3851

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-3850

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3850

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3850

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-3849

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-3849

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-3849

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-3848

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3848

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-3848

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2019-3847

почти 7 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2019-3810

почти 7 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-3810

почти 7 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-3810

почти 7 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-3809

почти 7 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-3809

почти 7 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-3809

почти 7 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsuppor ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-3851

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3851

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. T ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...

CVSS3: 8.8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3848

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3848

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3848

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3 ...

CVSS3: 4.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3847

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3810

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3810

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3810

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

CVSS3: 6.1
4%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsuppor ...

CVSS3: 6.5
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу