Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 469

Количество 2 469

github логотип

GHSA-prjm-2fj2-787f

около 2 лет назад

Moodle may allow teachers to access the names of users they could not otherwise access

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-ppvj-8723-v728

около 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

EPSS: Низкий
github логотип

GHSA-pj45-hp8h-289r

около 3 лет назад

Moodle Secure layout contained an insecure link in Boost theme

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-phqj-xp48-7p7c

около 3 лет назад

Moodle does not use the forceloginforprofiles setting for course-profiles access control

EPSS: Низкий
github логотип

GHSA-ph4r-v28v-v352

около 3 лет назад

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

EPSS: Низкий
github логотип

GHSA-pgp5-rcwp-qvfg

около 3 лет назад

Moodle includes the WebDAV password in the configuration form

EPSS: Низкий
github логотип

GHSA-pgm5-cr62-prxq

почти 3 года назад

Moodle Arbitrary file read when importing lesson questions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pgcp-m69h-p2gr

около 4 лет назад

Cross-site Scripting (XSS) in moodle

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pg89-qp74-vch2

около 3 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

EPSS: Низкий
github логотип

GHSA-p9hr-f4xj-8w8r

около 3 лет назад

Moodle included private user files in course backups

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p94v-4vwh-qwpf

около 3 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

EPSS: Низкий
github логотип

GHSA-p7v9-gjrh-563x

около 3 лет назад

Moodle XSS Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-p5j7-26wj-423j

около 3 лет назад

Moodle allows discovery of an author's username

EPSS: Низкий
github логотип

GHSA-p586-c547-p893

около 3 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

EPSS: Низкий
github логотип

GHSA-p497-37fc-xvvc

около 3 лет назад

Moodle allows attackers to cause a denial of service

EPSS: Низкий
github логотип

GHSA-p3hj-cfhm-7g6v

около 3 лет назад

Moodle allows attackers to remove wiki pages

EPSS: Низкий
github логотип

GHSA-p2cj-86v4-7782

около 1 года назад

Moodle HTTP authorization header is preserved between "emulated redirects"

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p269-r9cq-frhv

около 3 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

EPSS: Низкий
github логотип

GHSA-p239-x7hg-j3w6

около 3 лет назад

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

EPSS: Низкий
github логотип

GHSA-mxp2-wcjh-jf72

около 3 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-prjm-2fj2-787f

Moodle may allow teachers to access the names of users they could not otherwise access

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-ppvj-8723-v728

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

5%
Низкий
около 3 лет назад
github логотип
GHSA-pj45-hp8h-289r

Moodle Secure layout contained an insecure link in Boost theme

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-phqj-xp48-7p7c

Moodle does not use the forceloginforprofiles setting for course-profiles access control

0%
Низкий
около 3 лет назад
github логотип
GHSA-ph4r-v28v-v352

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pgp5-rcwp-qvfg

Moodle includes the WebDAV password in the configuration form

0%
Низкий
около 3 лет назад
github логотип
GHSA-pgm5-cr62-prxq

Moodle Arbitrary file read when importing lesson questions

CVSS3: 7.5
9%
Низкий
почти 3 года назад
github логотип
GHSA-pgcp-m69h-p2gr

Cross-site Scripting (XSS) in moodle

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-pg89-qp74-vch2

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p9hr-f4xj-8w8r

Moodle included private user files in course backups

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-p94v-4vwh-qwpf

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p7v9-gjrh-563x

Moodle XSS Vulnerability

CVSS3: 7.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-p5j7-26wj-423j

Moodle allows discovery of an author's username

0%
Низкий
около 3 лет назад
github логотип
GHSA-p586-c547-p893

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p497-37fc-xvvc

Moodle allows attackers to cause a denial of service

1%
Низкий
около 3 лет назад
github логотип
GHSA-p3hj-cfhm-7g6v

Moodle allows attackers to remove wiki pages

1%
Низкий
около 3 лет назад
github логотип
GHSA-p2cj-86v4-7782

Moodle HTTP authorization header is preserved between "emulated redirects"

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-p269-r9cq-frhv

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p239-x7hg-j3w6

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

0%
Низкий
около 3 лет назад
github логотип
GHSA-mxp2-wcjh-jf72

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу