Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2014-7837

больше 10 лет назад

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-7836

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7836

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-7836

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7835

больше 10 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-7835

больше 10 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-7835

больше 10 лет назад

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-7834

больше 10 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7834

больше 10 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7834

больше 10 лет назад

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-7833

больше 10 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7833

больше 10 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7833

больше 10 лет назад

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-7832

больше 10 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7832

больше 10 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7832

больше 10 лет назад

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-7831

больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7831

больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7831

больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-7830

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5.5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI ...

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

CVSS2: 2.1
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7835

webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2. ...

CVSS2: 2.1
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7834

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7833

mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7832

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x b ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7831

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7830

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу