Количество 2 536
Количество 2 536

CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the ...

CVE-2016-5014
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.

CVE-2016-5014
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
CVE-2016-5014
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor ...

CVE-2016-5013
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.

CVE-2016-5013
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
CVE-2016-5013
In Moodle 2.x and 3.x, text injection can occur in email headers, pote ...

CVE-2016-5012
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

CVE-2016-5012
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
CVE-2016-5012
In Moodle 3.x, glossary search displays entries without checking user ...

CVE-2016-3734
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.

CVE-2016-3734
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
CVE-2016-3734
Cross-site request forgery (CSRF) vulnerability in markposts.php in Mo ...

CVE-2016-3733
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

CVE-2016-3733
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
CVE-2016-3733
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through ...

CVE-2016-3732
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.

CVE-2016-3732
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the ... | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-5014 In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-5014 In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад |
CVE-2016-5014 In Moodle 2.x and 3.x, an unenrolled user still receives event monitor ... | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-5013 In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-5013 In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад |
CVE-2016-5013 In Moodle 2.x and 3.x, text injection can occur in email headers, pote ... | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-5012 In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-5012 In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-5012 In Moodle 3.x, glossary search displays entries without checking user ... | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-3734 Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read. | CVSS3: 8.8 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-3734 Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read. | CVSS3: 8.8 | 0% Низкий | больше 8 лет назад |
CVE-2016-3734 Cross-site request forgery (CSRF) vulnerability in markposts.php in Mo ... | CVSS3: 8.8 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-3733 The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-3733 The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-3733 The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through ... | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-3732 The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-3732 The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
Уязвимостей на страницу