Количество 2 469
Количество 2 469
GHSA-prjm-2fj2-787f
Moodle may allow teachers to access the names of users they could not otherwise access
GHSA-ppvj-8723-v728
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.
GHSA-pj45-hp8h-289r
Moodle Secure layout contained an insecure link in Boost theme
GHSA-phqj-xp48-7p7c
Moodle does not use the forceloginforprofiles setting for course-profiles access control
GHSA-ph4r-v28v-v352
backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.
GHSA-pgp5-rcwp-qvfg
Moodle includes the WebDAV password in the configuration form
GHSA-pgm5-cr62-prxq
Moodle Arbitrary file read when importing lesson questions
GHSA-pgcp-m69h-p2gr
Cross-site Scripting (XSS) in moodle
GHSA-pg89-qp74-vch2
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.
GHSA-p9hr-f4xj-8w8r
Moodle included private user files in course backups
GHSA-p94v-4vwh-qwpf
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
GHSA-p7v9-gjrh-563x
Moodle XSS Vulnerability
GHSA-p5j7-26wj-423j
Moodle allows discovery of an author's username
GHSA-p586-c547-p893
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
GHSA-p497-37fc-xvvc
Moodle allows attackers to cause a denial of service
GHSA-p3hj-cfhm-7g6v
Moodle allows attackers to remove wiki pages
GHSA-p2cj-86v4-7782
Moodle HTTP authorization header is preserved between "emulated redirects"
GHSA-p269-r9cq-frhv
Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.
GHSA-p239-x7hg-j3w6
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
GHSA-mxp2-wcjh-jf72
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-prjm-2fj2-787f Moodle may allow teachers to access the names of users they could not otherwise access | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-ppvj-8723-v728 Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424. | 5% Низкий | около 3 лет назад | ||
GHSA-pj45-hp8h-289r Moodle Secure layout contained an insecure link in Boost theme | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-phqj-xp48-7p7c Moodle does not use the forceloginforprofiles setting for course-profiles access control | 0% Низкий | около 3 лет назад | ||
GHSA-ph4r-v28v-v352 backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname. | 0% Низкий | около 3 лет назад | ||
GHSA-pgp5-rcwp-qvfg Moodle includes the WebDAV password in the configuration form | 0% Низкий | около 3 лет назад | ||
GHSA-pgm5-cr62-prxq Moodle Arbitrary file read when importing lesson questions | CVSS3: 7.5 | 9% Низкий | почти 3 года назад | |
GHSA-pgcp-m69h-p2gr Cross-site Scripting (XSS) in moodle | CVSS3: 6.1 | 0% Низкий | около 4 лет назад | |
GHSA-pg89-qp74-vch2 mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server. | 0% Низкий | около 3 лет назад | ||
GHSA-p9hr-f4xj-8w8r Moodle included private user files in course backups | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-p94v-4vwh-qwpf Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page. | 0% Низкий | около 3 лет назад | ||
GHSA-p7v9-gjrh-563x Moodle XSS Vulnerability | CVSS3: 7.3 | 0% Низкий | около 3 лет назад | |
GHSA-p5j7-26wj-423j Moodle allows discovery of an author's username | 0% Низкий | около 3 лет назад | ||
GHSA-p586-c547-p893 The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server. | 0% Низкий | около 3 лет назад | ||
GHSA-p497-37fc-xvvc Moodle allows attackers to cause a denial of service | 1% Низкий | около 3 лет назад | ||
GHSA-p3hj-cfhm-7g6v Moodle allows attackers to remove wiki pages | 1% Низкий | около 3 лет назад | ||
GHSA-p2cj-86v4-7782 Moodle HTTP authorization header is preserved between "emulated redirects" | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-p269-r9cq-frhv Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page. | 0% Низкий | около 3 лет назад | ||
GHSA-p239-x7hg-j3w6 blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed. | 0% Низкий | около 3 лет назад | ||
GHSA-mxp2-wcjh-jf72 The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу