Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2015-0216

около 10 лет назад

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-0216

около 10 лет назад

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-0215

около 10 лет назад

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-0215

около 10 лет назад

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-0215

около 10 лет назад

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-0214

около 10 лет назад

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-0214

около 10 лет назад

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-0214

около 10 лет назад

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2 ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-0213

около 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0213

около 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0213

около 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) edit ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0212

около 10 лет назад

Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-0212

около 10 лет назад

Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-0212

около 10 лет назад

Cross-site scripting (XSS) vulnerability in course/pending.php in Mood ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-0211

около 10 лет назад

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-0211

около 10 лет назад

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-0211

около 10 лет назад

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x be ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-9060

больше 10 лет назад

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-9060

больше 10 лет назад

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-9060

больше 10 лет назад

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x bef ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-0216

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0216

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0215

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0215

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0215

calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0214

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0214

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-services request, as demonstrated by a people-search request.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0214

message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2 ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.

CVSS2: 6.8
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) edit ...

CVSS2: 6.8
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0212

Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0212

Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted course summary.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0212

Cross-site scripting (XSS) vulnerability in course/pending.php in Mood ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0211

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0211

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0211

mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x be ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2014-9060

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.

CVSS2: 5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9060

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.

CVSS2: 5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9060

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x bef ...

CVSS2: 5
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу