Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-qm6h-hvwq-4xp6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.

EPSS: Низкий
github логотип

GHSA-qhc7-xhc2-7p7w

больше 1 года назад

Moodle self enrollment available before completing second factor with MFA enabled

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qh8m-6g4p-33h3

около 4 лет назад

Moodle Improper Authentication

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-qfh6-h7j6-fvjv

6 месяцев назад

Moodle formula injection vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qc86-vgf2-6fq6

больше 3 лет назад

Moodle SQL Injection vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-qc37-hv35-h42x

около 4 лет назад

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-q99x-mjmh-v8w7

больше 1 года назад

Moodle's user/power level management inconsistent with suspended users

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q6vw-27c6-jv9c

около 4 лет назад

Moodle Persistent Cross-site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-q5m8-g27f-797h

почти 4 года назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q53j-c866-h9mw

около 4 лет назад

Moodle doesn't properly check role

EPSS: Низкий
github логотип

GHSA-q3cm-ccrm-2mr6

около 2 лет назад

Moodle Authenticated LFI risk in some misconfigured shared hosting environments

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q34m-x5mm-6rwc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.

EPSS: Низкий
github логотип

GHSA-q2x3-2f9g-h559

больше 3 лет назад

Moodle's Mustache pix helper contained a potential Mustache injection risk if combined with user input

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-pxg4-xjp7-w9c5

больше 1 года назад

Moodle's feedback response viewing and deletions did not respect Separate Groups mode

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-px56-6vfj-h8xp

6 месяцев назад

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-prrh-679x-79qh

около 4 лет назад

Moodle allows remote authenticated users to reassign notes

EPSS: Низкий
github логотип

GHSA-prjm-2fj2-787f

больше 3 лет назад

Moodle may allow teachers to access the names of users they could not otherwise access

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-ppvj-8723-v728

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

EPSS: Низкий
github логотип

GHSA-pj96-xh2w-fgqx

больше 1 года назад

Moodle has an IDOR in messaging web service which allows access to some user details

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pj45-hp8h-289r

около 4 лет назад

Moodle Secure layout contained an insecure link in Boost theme

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qm6h-hvwq-4xp6

Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qhc7-xhc2-7p7w

Moodle self enrollment available before completing second factor with MFA enabled

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-qh8m-6g4p-33h3

Moodle Improper Authentication

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-qfh6-h7j6-fvjv

Moodle formula injection vulnerability

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-qc86-vgf2-6fq6

Moodle SQL Injection vulnerability

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qc37-hv35-h42x

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-q99x-mjmh-v8w7

Moodle's user/power level management inconsistent with suspended users

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-q6vw-27c6-jv9c

Moodle Persistent Cross-site Scripting (XSS)

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-q5m8-g27f-797h

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-q53j-c866-h9mw

Moodle doesn't properly check role

2%
Низкий
около 4 лет назад
github логотип
GHSA-q3cm-ccrm-2mr6

Moodle Authenticated LFI risk in some misconfigured shared hosting environments

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-q34m-x5mm-6rwc

Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-q2x3-2f9g-h559

Moodle's Mustache pix helper contained a potential Mustache injection risk if combined with user input

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pxg4-xjp7-w9c5

Moodle's feedback response viewing and deletions did not respect Separate Groups mode

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-px56-6vfj-h8xp

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVSS3: 7.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-prrh-679x-79qh

Moodle allows remote authenticated users to reassign notes

2%
Низкий
около 4 лет назад
github логотип
GHSA-prjm-2fj2-787f

Moodle may allow teachers to access the names of users they could not otherwise access

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-ppvj-8723-v728

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

3%
Низкий
около 4 лет назад
github логотип
GHSA-pj96-xh2w-fgqx

Moodle has an IDOR in messaging web service which allows access to some user details

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-pj45-hp8h-289r

Moodle Secure layout contained an insecure link in Boost theme

CVSS3: 4.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу