Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

ubuntu логотип

CVE-2015-5335

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5335

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5335

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/registration/ ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5332

больше 9 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-5332

больше 9 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2015-5332

больше 9 лет назад

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-5331

больше 9 лет назад

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5331

больше 9 лет назад

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5331

больше 9 лет назад

Moodle 2.9.x before 2.9.3 does not properly check the contact list bef ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5272

больше 9 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5272

больше 9 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5272

больше 9 лет назад

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authentic ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5269

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2015-5269

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2015-5269

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in group/overview.php in Mood ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-5268

больше 9 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5268

больше 9 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5268

больше 9 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5267

больше 9 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-5267

больше 9 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-5335

Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5335

Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5335

Cross-site request forgery (CSRF) vulnerability in admin/registration/ ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

CVSS3: 6.8
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote ...

CVSS3: 6.8
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5331

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5331

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5331

Moodle 2.9.x before 2.9.3 does not properly check the contact list bef ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5272

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5272

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5272

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authentic ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Mood ...

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад

Уязвимостей на страницу