Количество 2 469
Количество 2 469
GHSA-mw6p-49jf-9935
Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page
GHSA-mrrv-fq8p-rp6j
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
GHSA-mr97-gvvg-rhgh
Moodle Exposes Sensitive User Information
GHSA-mpjx-8phj-5m34
Moodle Allows Unauthenticated Dropbox Access
GHSA-mphj-h2fc-62x3
Moodle allows attackers to bypass the mod/lti:view capability requirement
GHSA-mmvj-j7hq-rx85
Moodle sensitive information disclosure
GHSA-mm9q-3847-m48x
Moodle allows attackers to enter additional answer attempts
GHSA-mm9p-xwfm-3fqf
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
GHSA-mm73-86f9-5x5c
Moodle Grade information disclosure in grade's external fetch functions
GHSA-mj85-3hqq-r6r9
Moodle Reflected XSS in mod_data advanced search
GHSA-mgqq-8x9v-jp4r
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
GHSA-mgfp-qcf2-pw3m
Moodle stored Cross-site Scripting (XSS)
GHSA-mg69-5q59-8jcg
Moodle does not enforce the moodle/site:accessallgroups capability requirement
GHSA-mg54-p2wj-5ph7
moodle: IDOR when fetching report schedules
GHSA-m98q-q59p-r9fv
Moodle open redirect vulnerability
GHSA-m97f-x4mr-4x3q
Moodle vulnerable to Cross-Site Request Forgery
GHSA-m939-6pxj-m7xx
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
GHSA-m8qh-hx4c-h9hr
Moodle has a CSRF risk in Brickfield tool's analysis request action
GHSA-m8f5-9wg8-2c3h
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-m882-j7gq-v9p7
Moodle allows attackers to obtain sensitive category-detail information
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-mw6p-49jf-9935 Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page | 0% Низкий | около 3 лет назад | ||
GHSA-mrrv-fq8p-rp6j Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php | 1% Низкий | около 3 лет назад | ||
GHSA-mr97-gvvg-rhgh Moodle Exposes Sensitive User Information | 0% Низкий | около 3 лет назад | ||
GHSA-mpjx-8phj-5m34 Moodle Allows Unauthenticated Dropbox Access | 0% Низкий | около 3 лет назад | ||
GHSA-mphj-h2fc-62x3 Moodle allows attackers to bypass the mod/lti:view capability requirement | 0% Низкий | около 3 лет назад | ||
GHSA-mmvj-j7hq-rx85 Moodle sensitive information disclosure | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-mm9q-3847-m48x Moodle allows attackers to enter additional answer attempts | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-mm9p-xwfm-3fqf Moodle Authenticated LFI risk in some misconfigured shared hosting environments | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-mm73-86f9-5x5c Moodle Grade information disclosure in grade's external fetch functions | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-mj85-3hqq-r6r9 Moodle Reflected XSS in mod_data advanced search | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-mgqq-8x9v-jp4r lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords. | 1% Низкий | около 3 лет назад | ||
GHSA-mgfp-qcf2-pw3m Moodle stored Cross-site Scripting (XSS) | CVSS3: 6.1 | 5% Низкий | около 3 лет назад | |
GHSA-mg69-5q59-8jcg Moodle does not enforce the moodle/site:accessallgroups capability requirement | 0% Низкий | около 3 лет назад | ||
GHSA-mg54-p2wj-5ph7 moodle: IDOR when fetching report schedules | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
GHSA-m98q-q59p-r9fv Moodle open redirect vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-m97f-x4mr-4x3q Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | около 3 лет назад | ||
GHSA-m939-6pxj-m7xx Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 1% Низкий | около 3 лет назад | ||
GHSA-m8qh-hx4c-h9hr Moodle has a CSRF risk in Brickfield tool's analysis request action | 0% Низкий | около 2 месяцев назад | ||
GHSA-m8f5-9wg8-2c3h Moodle multiple cross-site scripting (XSS) vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-m882-j7gq-v9p7 Moodle allows attackers to obtain sensitive category-detail information | CVSS3: 4.3 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу