Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

ubuntu логотип

CVE-2017-2578

больше 8 лет назад

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-2578

больше 8 лет назад

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-2578

больше 8 лет назад

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-2576

больше 8 лет назад

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-2576

больше 8 лет назад

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-2576

больше 8 лет назад

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes i ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-15110

больше 7 лет назад

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-15110

больше 7 лет назад

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-15110

больше 7 лет назад

In Moodle 3.x, students can find out email addresses of other students ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2017-12157

почти 8 лет назад

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-12157

почти 8 лет назад

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-12157

почти 8 лет назад

In Moodle 3.x, various course reports allow teachers to view details a ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2017-12156

почти 8 лет назад

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-12156

почти 8 лет назад

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-12156

почти 8 лет назад

Moodle 3.x has XSS in the contact form on the "non-respondents" page i ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9188

больше 8 лет назад

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-9188

больше 8 лет назад

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-9188

больше 8 лет назад

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9187

больше 8 лет назад

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-9187

больше 8 лет назад

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-2578

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-2578

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-2578

In Moodle 3.x, there is XSS in the assignment submission page.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

CVSS3: 5.3
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

CVSS3: 5.3
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes i ...

CVSS3: 5.3
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-15110

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-15110

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-15110

In Moodle 3.x, students can find out email addresses of other students ...

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-12157

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-12157

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-12157

In Moodle 3.x, various course reports allow teachers to view details a ...

CVSS3: 4.3
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-12156

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-12156

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-12156

Moodle 3.x has XSS in the contact form on the "non-respondents" page i ...

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ...

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
больше 8 лет назад

Уязвимостей на страницу