Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

github логотип

GHSA-pg89-qp74-vch2

больше 3 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

EPSS: Низкий
github логотип

GHSA-p9hr-f4xj-8w8r

больше 3 лет назад

Moodle included private user files in course backups

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p9cx-f595-h79h

около 1 года назад

Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p94v-4vwh-qwpf

больше 3 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

EPSS: Низкий
github логотип

GHSA-p7v9-gjrh-563x

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-p5j7-26wj-423j

больше 3 лет назад

Moodle allows discovery of an author's username

EPSS: Низкий
github логотип

GHSA-p5cg-6rfr-6mx8

больше 1 года назад

Moodle stored XSS via calendar's event title when deleting the event

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p586-c547-p893

больше 3 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

EPSS: Низкий
github логотип

GHSA-p497-37fc-xvvc

больше 3 лет назад

Moodle allows attackers to cause a denial of service

EPSS: Низкий
github логотип

GHSA-p3hj-cfhm-7g6v

больше 3 лет назад

Moodle allows attackers to remove wiki pages

EPSS: Низкий
github логотип

GHSA-p2cj-86v4-7782

больше 1 года назад

Moodle HTTP authorization header is preserved between "emulated redirects"

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p269-r9cq-frhv

больше 3 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

EPSS: Низкий
github логотип

GHSA-p239-x7hg-j3w6

больше 3 лет назад

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

EPSS: Низкий
github логотип

GHSA-mxp2-wcjh-jf72

больше 3 лет назад

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

EPSS: Низкий
github логотип

GHSA-mx26-62xm-2p83

около 1 года назад

Moodle vulnerable to site administration SQL injection via XMLDB editor

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-mw6p-49jf-9935

больше 3 лет назад

Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page

EPSS: Низкий
github логотип

GHSA-mrrv-fq8p-rp6j

больше 3 лет назад

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

EPSS: Низкий
github логотип

GHSA-mr97-gvvg-rhgh

больше 3 лет назад

Moodle Exposes Sensitive User Information

EPSS: Низкий
github логотип

GHSA-mpjx-8phj-5m34

больше 3 лет назад

Moodle Allows Unauthenticated Dropbox Access

EPSS: Низкий
github логотип

GHSA-mphj-h2fc-62x3

больше 3 лет назад

Moodle allows attackers to bypass the mod/lti:view capability requirement

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pg89-qp74-vch2

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p9hr-f4xj-8w8r

Moodle included private user files in course backups

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-p9cx-f595-h79h

Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-p94v-4vwh-qwpf

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p7v9-gjrh-563x

Moodle XSS Vulnerability

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p5j7-26wj-423j

Moodle allows discovery of an author's username

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p5cg-6rfr-6mx8

Moodle stored XSS via calendar's event title when deleting the event

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-p586-c547-p893

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p497-37fc-xvvc

Moodle allows attackers to cause a denial of service

1%
Низкий
больше 3 лет назад
github логотип
GHSA-p3hj-cfhm-7g6v

Moodle allows attackers to remove wiki pages

1%
Низкий
больше 3 лет назад
github логотип
GHSA-p2cj-86v4-7782

Moodle HTTP authorization header is preserved between "emulated redirects"

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-p269-r9cq-frhv

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p239-x7hg-j3w6

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mxp2-wcjh-jf72

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mx26-62xm-2p83

Moodle vulnerable to site administration SQL injection via XMLDB editor

CVSS3: 7.2
0%
Низкий
около 1 года назад
github логотип
GHSA-mw6p-49jf-9935

Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mrrv-fq8p-rp6j

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

1%
Низкий
больше 3 лет назад
github логотип
GHSA-mr97-gvvg-rhgh

Moodle Exposes Sensitive User Information

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mpjx-8phj-5m34

Moodle Allows Unauthenticated Dropbox Access

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mphj-h2fc-62x3

Moodle allows attackers to bypass the mod/lti:view capability requirement

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу