Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

ubuntu логотип

CVE-2015-3273

почти 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3273

почти 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3273

почти 10 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3272

почти 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2015-3272

почти 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2015-3272

почти 10 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-3181

больше 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-3181

больше 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-3181

больше 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-3180

больше 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-3180

больше 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-3180

больше 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-3179

больше 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3179

больше 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3179

больше 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3178

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3178

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3178

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3177

больше 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3177

больше 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3273

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the ...

CVSS3: 4.3
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу